CVE-2023-36932 is a critical SQL injection vulnerability affecting multiple versions of Progress MOVEit Transfer before specific patch levels. An authenticated attacker can exploit this flaw by submitting a crafted payload to a web application endpoint, potentially gaining unauthorized access to the MOVEit Transfer database, leading to modification and disclosure of its contents. With a CVSS score of 8.1 (HIGH), this vulnerability has a low attack complexity and requires only authenticated access, posing a significant risk of high impact to confidentiality and integrity. While there is no confirmed active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion and media coverage, indicating high awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.1.11CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.0, < 2021.0.9CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2021.1.0, < 2021.1.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.0.0, < 2022.0.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 2022.1.0, < 2022.1.8CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.