CVE-2018-6545: Ipswitch MOVEit

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks.

Affected products

Published 2018-02-02. Last modified 2026-06-17.