Progress Moveit Transfer vulnerabilities

26 known vulnerabilities affecting progress/moveit_transfer.

Total CVEs
26
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH13MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2021-37614HIGHCVSS 8.8fixed in 2019.0.7≥ 2019.1, < 2019.1.6+4 more2021-08-05
CVE-2021-37614 [HIGH] CWE-89 CVE-2021-37614: In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVE In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the struc
nvd
CVE-2021-33894HIGHCVSS 8.8fixed in 2019.0.6≥ 2019.1, < 2019.1.5+4 more2021-06-09
CVE-2021-33894 [HIGH] CWE-89 CVE-2021-33894: In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x be In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in SILUtility.vb in MOVEit.DMZ.WebApp in the MOVEit Transfer web app. This could allow a
nvd
CVE-2021-31827HIGHCVSS 8.8fixed in 2021.02021-05-18
CVE-2021-31827 [HIGH] CWE-89 CVE-2021-31827: In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in th In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer info
nvd
CVE-2020-28647MEDIUMCVSS 5.4fixed in 2020.12020-11-17
CVE-2020-28647 [MEDIUM] CWE-79 CVE-2020-28647: In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within t In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
nvd
CVE-2020-8612CRITICALCVSS 9.0≥ 2019.2, < 2019.2.12020-02-14
CVE-2020-8612 [CRITICAL] CWE-79 CVE-2020-8612: In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint f In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
nvd
CVE-2020-8611HIGHCVSS 8.8≥ 2019.2, < 2019.2.12020-02-14
CVE-2020-8611 [HIGH] CWE-89 CVE-2020-8611: In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injectio In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL)
nvd