← Browse

CVE-2023-34362

Act now ● On CISA KEV — actively exploited used in ransomware

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
99.9%
100.0th percentile
CISA KEV
Listed
Added 2023-06-02 · patch by 2023-06-23
Weakness / dates
Published — · modified —

Description

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Official: NVD · CVE.org