CriticalCVECISA — Known Exploited Vulnerabilities· 2 Jun 2023

CVE-2023-34362 — Progress MOVEit Transfer SQL Injection Vulnerability

Severity: Critical · Kind: Vulnerability

Plain-English summary on the way

We've ingested this item but haven't summarised it yet. Read the upstream advisory using the link below in the meantime — the AI summary will appear here once the next run completes.

From the source

Progress MOVEit Transfer. Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. Required action: Apply updates per vendor instructions.

Vulnerability facts

CVE
CVE-2023-34362
On CISA KEV since
2023-06-02
Ransomware use
Known

Was this useful?

00000Sign in to react

Plain-English summaries are AI-generated and reviewed for tone, not technical accuracy. For incident response, always rely on the original source linked above.