Description
Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), is vulnerable to an SQL injection vulnerability that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database and execute SQL statements that alter or delete database elements.
Remediation
Patches for all supported MOVEit Transfer versions are available.
References
MOVEit Transfer Critical Vulnerability (May 2023)
MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Multiple Vulnerabilities (4.3.5)
WordPress Plugin Broken Link Manager SQL Injection (0.6.5)
WordPress Plugin Social Slider 'rA[]' Parameter SQL Injection (5.6.5)
WordPress Plugin Loginizer SQL Injection (1.6.3)
WordPress 'comment_post_ID' Parameter SQL Injection Vulnerability (3.0.4)