CVE-2023-36934: Progress MOVEit Transfer
Critical severity, CVSS 9.1. EPSS: 95.2% chance of exploitation in the next 30 days.
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
Affected products
- Progress MOVEit Transfer: before 12.1.11 (fixed in 12.1.11); from 13.0.0, before 13.0.9 (fixed in 13.0.9); from 13.1.0, before 13.1.7 (fixed in 13.1.7); from 14.0.0, before 14.0.7 (fixed in 14.0.7); from 14.1.0, before 14.1.8 (fixed in 14.1.8); from 15.0.0, before 15.0.4 (fixed in 15.0.4)
Published 2023-07-05. Last modified 2026-06-17.