CVE-2023-42660: MOVEit Transfer Machine Interface SQL Injection
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-42660?
CVE-2023-42660 is a SQL injection vulnerability in MOVEit Transfer versions released before 2021.1.8, 2022.0.8, 2022.1.9, and 2023.0.6.
How can an attacker exploit CVE-2023-42660?
An attacker can exploit CVE-2023-42660 by using SQL injection techniques to gain unauthorized access to the MOVEit Transfer machine interface.
What is the severity of CVE-2023-42660?
CVE-2023-42660 has a severity rating of 8.8 (high).
Which versions of MOVEit Transfer are affected by CVE-2023-42660?
MOVEit Transfer versions released before 2021.1.8, 2022.0.8, 2022.1.9, and 2023.0.6 are affected by CVE-2023-42660.
How do I fix CVE-2023-42660?
To fix CVE-2023-42660, you should upgrade to MOVEit Transfer version 2021.1.8 or later.