Vulnerability record · CVE-2023-36932 · published 5 July 2023
CVE-2023-36932: Progress MOVEit Transfer SQL injection in web application
Progress · Moveit Transfer
MOVEit Transfer versions before the listed July 2023 service packs contain multiple SQL injection flaws in the web application. An authenticated attacker can submit crafted payloads to application endpoints, allowing modification and disclosure of MOVEit database content. The flaw matters because it exposes the product's core database to a user who already holds a valid account.
Description
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityCVSS 8.1 with high confidentiality and integrity impact and a very high EPSS score, though exploitation requires authentication and no KEV listing or public exploit is confirmed.
What it is
MOVEit Transfer versions before the listed July 2023 service packs contain multiple SQL injection flaws in the web application. An authenticated attacker can submit crafted payloads to application endpoints, allowing modification and disclosure of MOVEit database content. The flaw matters because it exposes the product's core database to a user who already holds a valid account.
Impact
An attacker gains unauthorized read and write access to the MOVEit Transfer database, enabling disclosure and modification of stored data. Integrity and confidentiality are both rated high; availability is not affected.
Attack surface
Reachable over the network through MOVEit Transfer web application endpoints. Authentication is required (PR:L) and no user interaction is needed (UI:N).
Exploitation
Not listed in CISA KEV and no ransomware group usage is documented. EPSS is very high (0.81092, 99.6th percentile), but the references are only vendor release notes and product pages, so no public exploit code is confirmed by this record.
What to do
- Apply the vendor service packs that fix the issue: 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4).
- If immediate patching is not possible, restrict and monitor authenticated access to MOVEit Transfer web endpoints.
- Review MOVEit Transfer accounts and remove or disable unnecessary authenticated users.
- Audit database permissions used by the MOVEit Transfer application to limit write scope.
- Monitor vendor advisory page for updated guidance.
Detection
- Review MOVEit Transfer web logs for SQL metacharacters or injection-like patterns in request parameters.
- Alert on unusual database queries or errors originating from the MOVEit Transfer application.
- Baseline normal authenticated user activity and flag anomalous database reads or writes.
- Correlate MOVEit Transfer access with database audit logs for unexpected modification of content.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023 | Release NotesVendor Advisory |
| https://www.progress.com/moveit | Product |
| https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023 | Release NotesVendor Advisory |
| https://www.progress.com/moveit | Product |
Track CVE-2023-36932 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-36932), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.