Progress moveit transfer是Progress公司的一款文件传输软件。 Progress MOVEit Transfer 2025.1.0版本至2025.1.3之前版本和2025.0.7之前版本存在授权问题漏洞,该漏洞源于基于欺骗的绕过身份验证,可能导致未经身份验证的攻击者通过HTTPS模块绕过身份验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | MOVEit Transfer | 2025.1.0< 2025.1.3 |
affected |
< 2025.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress | MOVEit Transfer | 2025.1.0 ~ 2025.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11903 | 8.0 HIGH | Stored XSS in MOVEit Transfer Ad Hoc module |
| CVE-2026-10699 | 7.5 HIGH | Memory leak in SFTP service can result in a denial of service in MOVEit Transfer |
| CVE-2026-10698 | 7.2 HIGH | Table scope bypass vulnerability in custom reports |
| CVE-2026-8649 | 6.4 MEDIUM | Institution scope bypass vulnerability in custom reports |
| CVE-2026-8650 | 4.5 MEDIUM | Authenticated Path Traversal allows MOVEit admins to view arbitrary system files |
| CVE-2026-8801 | 3.5 LOW | File Extension Restriction Bypass in MOVEit Transfer |
| CVE-2026-8800 | 2.7 LOW | Cross-Org External Token Metadata accessible to AuditUser role |
No comments yet