CVE record
CVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
unknown
No parseable CVSS vector returned
Affected packages
0
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Progress
- Product
- MOVEit Transfer
- Date added
- Jun 2, 2023
- CISA federal remediation due date
- Jun 23, 2023
- Required action
- Apply updates per vendor instructions.
- Known ransomware campaign use
- Known
- CWE
- CWE-89
OSV package mapping