CVE-2023-34362
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 2, 2023
Updated: Dec 20, 2024
CWE ID 89
Summary
CVE-2023-34362 is a SQL injection vulnerability affecting MOVEit Transfer versions before 2021.0.6, 2021.1.4, 2022.0.4, 2022.1.5, and 2023.0.1. Unauthenticated attackers can exploit this flaw to gain access to the MOVEit Transfer database, potentially inferring its structure and contents or executing SQL statements to alter or delete database elements. The vulnerability, which has been exploited in the wild in May and June 2023, can be exploited via HTTP or HTTPS. All versions, including older unsupported ones, are at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Progress MOVEit File Transfer
- MOVEit Cloud
Affected Vendors
- Ipswitch, Inc.
- Progress Publishers