Progress Software flags three new vulnerabilities in MOVEit Transfer

General News

Summary

The vulnerability was discovered by Guy Lederfein as part of Trend Micro’s Zero Day Initiative, and affects versions of MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4). One (CVE-2023-36932) outlines “multiple” SQL vulnerabilities that can also allow for disclosure and modification of database content, affecting versions of MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), 2023.0.4 (15.0.4). The company credits HackerOne bug hunters cchav3z, nicolas_zilio and hoangha2, hoangnx, and duongdpt with VCSLAB of Viettel Cyber Security for discovering the vulnerabilitt. The newly reported flaws come on the heels of multiple disclosed SQL injection vulnerabilities reported in MOVEit Transfer and MOVEit Cloud in May and June, at least one of which was exploited by the Cl0p extortion group, resulting in dozens of companies disclosing that their data was stolen in the attack. Cl0p has listed nearly 200 companies thus far on its dark web leak page, and experts expect more victims to be discovered in the coming weeks and months.

Classifications

industries
No industries detected
applications
Business Planning / Continuity

AskAI Classifications

Labels
Enterprise Software SaaS Developer Tools

Linked Companies