QID 378876

Date Published: 2023-09-22

QID 378876: Progress MOVEit Transfer Multiple Security Vulnerabilities (September 2023)

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6) are vulnerable to SQL Injection and Cross-Site Scripting (XSS) attacks.

Affected Versions:
Progress MOVEit Transfer versions prior to 2021.1.8 (13.1.8)
Progress MOVEit Transfer versions prior to 2022.0.8 (14.0.8)
Progress MOVEit Transfer versions prior to 2022.1.9 (14.1.9)
Progress MOVEit Transfer versions prior to 2023.0.6 (15.0.6)

QID Detection Logic: (Authenticated)
This QID checks file version of MOVEit.DMZ.ClassLib.dll to identify the vulnerable versions of the product MOVEit Transfer.

QID Detection Logic: (Unauthenticated)
This QID checks vulnerable version of MOVEit Transfer by sending a HTTP GET request to '/moveitisapi/moveitisapi.dll?action=capa' endpoint and checking the X-MOVEitISAPI-Version header.

Successful exploitation of the vulnerability may allow an attacker to perform SQL Injection and/or Cross-Site Scripting (XSS) attacks.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to refer to the article Article 000241629 for more information regarding the vulnerability and its related patches.

    CVEs related to QID 378876

    Software Advisories
    Advisory ID Software Component Link
    000241629 URL Logo community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023