PromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2023-34362 - Progress MOVEit Transfer

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete datab...

AI Vulnerability ContextCISA KEVProgress

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2023-34362
Vendor/project
Progress
Product
MOVEit Transfer
Vulnerability name
Progress MOVEit Transfer SQL Injection Vulnerability
Date added
2023-06-02
Due date
2023-06-23
Known ransomware campaign use
Known
CWE-89

Exploit context

What the vulnerability is about.

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

Source

Where this page information comes from.