CVE-2023-35708

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 16, 2023
Updated: Jun 20, 2023
CWE ID 89

Summary

CVE-2023-35708 is a newly identified SQL injection vulnerability affecting MOVEit Transfer versions before 2021.0.8, 2021.1.6, 2022.0.6, 2022.1.7, and 2023.0.3. An attacker can exploit this vulnerability by submitting a specially crafted payload to a MOVEit Transfer application endpoint. This could allow the attacker to gain unauthenticated access to the MOVEit Transfer database and modify or disclose its content. The affected versions have been patched in updates 2020.1.10, 2021.0.8, 2021.1.6, 2022.0.6, 2022.1.7, and 2023.0.3. System administrators are strongly advised to apply these patches as soon as possible to mitigate the risk of potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Progress MOVEit File Transfer

Affected Vendors

  • Ipswitch, Inc.

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-35708 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions