Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmqw-pc9c-vx39

Опубликовано: 20 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system administrator

could submit a crafted payload to the MOVEit Transfer web interface which could result in modification and disclosure of MOVEit database content.

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system administrator

could submit a crafted payload to the MOVEit Transfer web interface which could result in modification and disclosure of MOVEit database content.

EPSS

Процентиль: 64%
0.00468
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
nvd
больше 2 лет назад

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit Transfer database. A MOVEit system administrator could submit a crafted payload to the MOVEit Transfer web interface which could result in modification and disclosure of MOVEit database content.

CVSS3: 7.2
fstec
больше 2 лет назад

Уязвимость веб-интерфейса программного обеспечения для обработки и передачи конфиденциальных данных Progress MOVEit Transfer, связанная с отсутствием проверки достоверности последовательностей XML-объетов, позволяющая нарушителю получить несанкционированный доступ к базе данных MOVEit Transfer

EPSS

Процентиль: 64%
0.00468
Низкий

7.2 High

CVSS3

Дефекты

CWE-89