ZDI-23-897: Progress Software MOVEit Transfer UserProcessPassChangeRequest SQL Injection Remote Code Execution Vulnerability
Published Jul 5, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software MOVEit Transfer. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Progress Software MOVEit Transfer
Event History
Jul 5, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-897?
ZDI-23-897 has a high severity rating due to its ability to allow remote code execution without authentication.
2
How do I fix ZDI-23-897?
To fix ZDI-23-897, apply the latest security updates provided by Progress Software for MOVEit Transfer.
3
What systems are affected by ZDI-23-897?
ZDI-23-897 affects installations of Progress Software MOVEit Transfer.
4
Can ZDI-23-897 be exploited without authentication?
Yes, ZDI-23-897 can be exploited by remote attackers without the need for authentication.
5
What are the potential impacts of ZDI-23-897?
Exploitation of ZDI-23-897 can lead to arbitrary code execution on affected systems, compromising their security.