DEV Community

Cover image for CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability
Freedom Coder
Freedom Coder

Posted on • Originally published at scyscan.com

CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

CVE ID

CVE-2023-34362

Vulnerability Name

Progress MOVEit Transfer SQL Injection Vulnerability

  • Project: Progress
  • Product: MOVEit Transfer

Date

  • Date Added: 2023-06-02
  • Due Date: 2023-06-23

Description

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply updates per vendor instructions.

Additional Notes

This CVE has a CISA AA located here: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a. Please see the AA for associated IOCs. Additional information is available at: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023.; https://nvd.nist.gov/vuln/detail/CVE-2023-34362

Related Security News

More CVEs Info

Common Vulnerabilities & Exposures (CVE) List

Top comments (0)