Progress MOVEit Transfer是Progress公司的一款文件传输软件。 Progress MOVEit Transfer 2025.1.5之前版本和2026.0.3之前的2026.0.0版本存在跨站脚本漏洞,该漏洞源于网页生成期间输入中和不当,可能导致跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | MOVEit Transfer | < 2025.1.5 |
affected |
2026.0.0< 2026.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress | MOVEit Transfer | 0 ~ 2025.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15966 | 7.5 HIGH | Improper CORS handling in MOVEit Transfer |
| CVE-2026-15967 | 7.5 HIGH | MOVEit Transfer refresh-token processing does not enforce updated account restrictions |
| CVE-2026-10697 | 7.5 HIGH | MFA Bypass in MOVEit Transfer |
No comments yet