CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. Required action: Apply updates per vendor instructions.
· high severity · unattributed attribution
Evidence and provenance
- Original source
- CISA KEV report ↗
- Published
- 2023-06-02T00:00:00Z
- Confidence basis
- No actor match
- Record ID
c5d772f30dad791347eb
Vulnerabilities
CVE-2023-34362
Use and citation
Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.