CVE-2023-36934 is a critical SQL injection vulnerability affecting Progress MOVEit Transfer versions before 2020.1.11, 2021.0.9, 2021.1.7, 2022.0.7, 2022.1.8, and 2023.0.4. This flaw allows an unauthenticated attacker to gain unauthorized access to and modify or disclose the MOVEit Transfer database content by submitting a crafted payload. With a CVSS score of 9.1 (CRITICAL), it has a low attack complexity and requires no user interaction, leading to high confidentiality and integrity impacts. While not yet in the KEV catalog, there is evidence of active scanning for vulnerable systems, Nuclei templates are available, and the vulnerability has garnered significant community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.11CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 13.0.0, < 13.0.9CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 13.1.0, < 13.1.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 14.0.0, < 14.0.7CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | ||
>= 14.1.0, < 14.1.8CPE matchmatch criteria | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.