CVE-2020-28647: XSS
In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28647?
CVE-2020-28647 is a vulnerability in In Progress MOVEit Transfer before 2020.1 that allows a malicious user to execute arbitrary code within a victim's browser.
How does CVE-2020-28647 work?
CVE-2020-28647 allows a malicious user to craft and store a payload within the MOVEit Transfer application, which can be executed when a victim interacts with it.
What is the severity of CVE-2020-28647?
The severity of CVE-2020-28647 is medium with a CVSS score of 5.4.
How can I fix CVE-2020-28647?
To fix CVE-2020-28647, it is recommended to update to MOVEit Transfer version 2020.1 or later.
Where can I find more information about CVE-2020-28647?
More information about CVE-2020-28647 can be found in the references provided: [link1], [link2], [link3].