CVE-2020-28647: Progress MOVEit Transfer
Medium severity, CVSS 5.4. EPSS: 1.5% chance of exploitation in the next 30 days.
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Affected products
- Progress MOVEit Transfer: before 2020.1 (fixed in 2020.1)
Published 2020-11-17. Last modified 2026-06-17.