Security
Loading…

CVE-2023-34362

UNKNOWNKnown Exploited
Description

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Timeline
Published:June 2nd, 2023 12:00 AM
Last modified:June 2nd, 2023 12:00 AM
Added to KEV:June 2nd, 2023
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Progress

Products

MOVEit Transfer
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute