CVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
⚠ KEVEPSS 99.9%
Description
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
How to fix CVE-2023-34362
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2023-34362 being exploited?
Yes — CVE-2023-34362 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.