Progress moveit transfer是Progress公司的一款文件传输软件。 Progress MOVEit Transfer存在跨站脚本漏洞,该漏洞源于Ad Hoc module中存在Web页面生成时输入中和不当,容易受到跨站脚本攻击。以下版本受到影响:2026.0.1版本之前的2026.0.0版本、2025.1.4版本之前的2025.1.0版本和2025.0.8版本之前的2025.0.0版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | MOVEit Transfer | 2026.0.0< 2026.0.1 |
affected |
2025.1.0< 2025.1.4 |
affected | ||
2025.0.0< 2025.0.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress | MOVEit Transfer | 2026.0.0 ~ 2026.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10699 | 7.5 HIGH | Memory leak in SFTP service can result in a denial of service in MOVEit Transfer |
| CVE-2026-10698 | 7.2 HIGH | Table scope bypass vulnerability in custom reports |
| CVE-2026-8649 | 6.4 MEDIUM | Institution scope bypass vulnerability in custom reports |
| CVE-2026-8650 | 4.5 MEDIUM | Authenticated Path Traversal allows MOVEit admins to view arbitrary system files |
| CVE-2026-8651 | 3.7 LOW | IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer |
| CVE-2026-8801 | 3.5 LOW | File Extension Restriction Bypass in MOVEit Transfer |
| CVE-2026-8800 | 2.7 LOW | Cross-Org External Token Metadata accessible to AuditUser role |
No comments yet