First published: Tue Nov 17 2020(Updated: )
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress MOVEit Transfer | <2020.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28647 is a vulnerability in In Progress MOVEit Transfer before 2020.1 that allows a malicious user to execute arbitrary code within a victim's browser.
CVE-2020-28647 allows a malicious user to craft and store a payload within the MOVEit Transfer application, which can be executed when a victim interacts with it.
The severity of CVE-2020-28647 is medium with a CVSS score of 5.4.
To fix CVE-2020-28647, it is recommended to update to MOVEit Transfer version 2020.1 or later.
More information about CVE-2020-28647 can be found in the references provided: [link1], [link2], [link3].