Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2023-34362KEVEXPLOITEDPATCHED
progress · moveit_cloud

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfe

Description

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

Affected Products

VendorProductVersions
progressmoveit_cloud< 14.0.5.45, < 14.1.6.97, < 15.0.2.39, < 2021.0.7, < 2021.1.5, < 2022.0.5, < 2022.1.6, < 2023.0.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
progressmoveit_transfercve_cpe95%

References

  • http://packetstormsecurity.com/files/172883/MOVEit-Transfer-SQL-Injection-Remote-Code-Execution.html(Third Party Advisory, VDB Entry)
  • http://packetstormsecurity.com/files/173110/MOVEit-SQL-Injection.html(Exploit, Third Party Advisory, VDB Entry)
  • https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023(Vendor Advisory)
  • http://packetstormsecurity.com/files/172883/MOVEit-Transfer-SQL-Injection-Remote-Code-Execution.html(Third Party Advisory, VDB Entry)
  • http://packetstormsecurity.com/files/173110/MOVEit-SQL-Injection.html(Exploit, Third Party Advisory, VDB Entry)
  • https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023(Vendor Advisory)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-34362(US Government Resource)

Related News (2 articles)

Tier D
BleepingComputer2d ago
SickKids data breach exposes employee and job applicant info
→ No new info (linked only)
Tier D
The Hacker News5d ago
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.94(Top 0%)
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
14.0.5.4514.1.6.9715.0.2.392021.0.72021.1.52022.0.52022.1.62023.0.2
CWECWE-89, CWE-89
PublishedJun 2, 2023
Last enriched144d ago
Trending Score89
Source articles2
Independent2
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 22
HIGHCVE-2026-16138
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Trending: 22
HIGHCVE-2026-16137
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Trending: 22
CRITICALCVE-2026-8037EXPKEV
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 21
HIGHCVE-2026-59689
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Trending: 15

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jun 2, 2023
Added to CISA KEV
Jun 2, 2023
Actively Exploited
Oct 27, 2025
Exploit Available
Oct 27, 2025
Patch Available
Oct 27, 2025
Discovered by ZDM
Apr 1, 2026