CVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
MITRE ATT&CK techniques
How this vulnerability maps to adversary behaviour, from the Center for Threat-Informed Defense's public CVE→ATT&CK mappings. Use it to check whether your detections already cover the technique.
| Technique | Name | Relationship |
|---|---|---|
| T1190 | Exploit Public-Facing Application | exploitation technique |
| T1059 | Command and Scripting Interpreter | primary impact |
| T1005 | Data from Local System | secondary impact |
| T1082 | System Information Discovery | secondary impact |
| T1105 | Ingress Tool Transfer | secondary impact |
| T1136 | Create Account | secondary impact |
| T1531 | Account Access Removal | secondary impact |
Summary
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
Affected software
Vendor: Progress · Product: MOVEit Transfer
Weakness types (CWE):
What to do
This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.
Related vulnerabilities in Progress
| CVE | Name | EPSS | Exploited |
|---|---|---|---|
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerabi | 99.7% | Yes |
| CVE-2024-4885 | Progress WhatsUp Gold Path Traversal Vulnerability | 99.3% | Yes |
| CVE-2024-4358 | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability | 97.5% | Yes |
| CVE-2024-1212 | Progress Kemp LoadMaster OS Command Injection Vulnerability | 95.4% | Yes |
| CVE-2024-6670 | Progress WhatsUp Gold SQL Injection Vulnerability | 94.7% | Yes |
| CVE-2023-40044 | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability | 90.2% | Yes |
| CVE-2017-9248 | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulne | 75.1% | Yes |
Is your domain exposed?
Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.
Get your free reportAll information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.