QID 379168
QID 379168: Progress MOVEit Transfer Multiple Security Vulnerabilities (November-2023)
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7) are vulnerable
Affected Versions:
Progress MOVEit Transfer versions prior to 2022.0.9 (14.0.9)
Progress MOVEit Transfer versions prior to 2022.1.10 (14.1.10)
Progress MOVEit Transfer versions prior to 2023.0.7 (15.0.7)
QID Detection Logic: (Authenticated)
This QID checks file version of MOVEit.DMZ.ClassLib.dll to identify the vulnerable versions of the product MOVEit Transfer.
QID Detection Logic: (Unauthenticated)
This QID checks vulnerable version of MOVEit Transfer by sending a HTTP GET request to '/moveitisapi/moveitisapi.dll?action=capa' endpoint and checking the X-MOVEitISAPI-Version header.
Successful exploitation of the vulnerability may allow an attacker to perform SQL Injection and/or Cross-Site Scripting (XSS) attacks.
- MOVEit Security Advisory -
community.progress.com/s/article/MOVEit-Transfer-Service-Pack-November-2023
CVEs related to QID 379168
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| November-2023 |
|