CVE-2023-35036
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2023-35036 is a newly discovered SQL injection vulnerability affecting MOVEit Transfer versions before 2023.0.2 (15.0.2). This issue, which exists in the MOVEit Transfer web application, can be exploited by unauthenticated attackers. By submitting specially crafted payloads to certain application endpoints, attackers can gain unauthorized access to the MOVEit Transfer database, leading to potential disclosure and modification of sensitive information. This vulnerability poses a serious threat and requires immediate attention and remediation from affected organizations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Progress MOVEit File Transfer
Affected Vendors
- Ipswitch, Inc.