CVE-2023-35036

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jun 12, 2023
Updated: Jan 3, 2025
CWE ID 89

Summary

CVE-2023-35036 is a newly discovered SQL injection vulnerability affecting MOVEit Transfer versions before 2023.0.2 (15.0.2). This issue, which exists in the MOVEit Transfer web application, can be exploited by unauthenticated attackers. By submitting specially crafted payloads to certain application endpoints, attackers can gain unauthorized access to the MOVEit Transfer database, leading to potential disclosure and modification of sensitive information. This vulnerability poses a serious threat and requires immediate attention and remediation from affected organizations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Progress MOVEit File Transfer

Affected Vendors

  • Ipswitch, Inc.