CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability
Freedom Coder

Freedom Coder @freedom_coder

About: love coding.

Joined:
Apr 17, 2025

CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

Publish Date: Jun 27
0 0

CVE ID

CVE-2023-34362

Vulnerability Name

Progress MOVEit Transfer SQL Injection Vulnerability

  • Project: Progress
  • Product: MOVEit Transfer

Date

  • Date Added: 2023-06-02
  • Due Date: 2023-06-23

Description

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply updates per vendor instructions.

Additional Notes

This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.; https://nvd.nist.gov/vuln/detail/CVE-2023-34362

Related Security News

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Comments 0 total

    Add comment