CVE-2020-28647: Progress MOVEit Transfer

Medium severity, CVSS 5.4. EPSS: 1.5% chance of exploitation in the next 30 days.

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).

Affected products

  • Progress MOVEit Transfer: before 2020.1 (fixed in 2020.1)

Published 2020-11-17. Last modified 2026-06-17.