AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2023-34362.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSCISA known exploitedAdded Jun 02, 2023
RECORD STATUSAwaiting NVD dataModified Jun 02, 2023

Disclosure summary

Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements.

CISA remediation guidance

Apply updates per vendor instructions.

Original records & references

PUBLISHED 2023-06-02T00:00:00-04:00
MODIFIED 2023-06-02T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00