Progress moveit transfer是Progress公司的一款文件传输软件。 Progress MOVEit Transfer 2025.0.7之前版本和2025.1.0至2025.1.3之前版本存在输入验证错误漏洞,该漏洞源于Data Query Logic中特殊元素中和不当,可能导致攻击者在Custom Reports modules中进行数据查询逻辑注入攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | MOVEit Transfer | 2025.1.0< 2025.1.3 |
affected |
< 2025.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress | MOVEit Transfer | 2025.1.0 ~ 2025.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11903 | 8.0 HIGH | Stored XSS in MOVEit Transfer Ad Hoc module |
| CVE-2026-10699 | 7.5 HIGH | Memory leak in SFTP service can result in a denial of service in MOVEit Transfer |
| CVE-2026-10698 | 7.2 HIGH | Table scope bypass vulnerability in custom reports |
| CVE-2026-8650 | 4.5 MEDIUM | Authenticated Path Traversal allows MOVEit admins to view arbitrary system files |
| CVE-2026-8651 | 3.7 LOW | IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer |
| CVE-2026-8801 | 3.5 LOW | File Extension Restriction Bypass in MOVEit Transfer |
| CVE-2026-8800 | 2.7 LOW | Cross-Org External Token Metadata accessible to AuditUser role |
No comments yet