CVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
⚠ KEVEPSS 99.9%
描述
Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.
如何修補 CVE-2023-34362
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2023-34362 正在被利用嗎?
是 — CVE-2023-34362 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。