CVE detail
CVE-2023-35036
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
Analysis of ransomware gang leak site data reveals significant activity over 2023. As groups formed — or dissolved — and tactics changed, we synthesize our findings.
vendorunit42.paloaltonetworks.comFeb 5, 2024, 11:00 AMProgress Software could be staring at fresh litigation over the explosive zero-day found in its file-transfer service, MOVEit, which affected millions of end users globally. The latest probe comes from the US Security and Exchange Commission (SEC), which is seeking information related to the mass hack. “On October 2, 2023, Progress received a subpoena from […]
newswww.csoonline.comOct 12, 2023, 11:43 AMThis threat brief details the critical vulnerability CVE-2023-34362 found in MOVEit Transfer and includes Unit 42's observations, the current attack scope and interim guidance.
vendorunit42.paloaltonetworks.comOct 4, 2023, 1:00 PMIndustry leaders across cybersecurity, networking, and service providers have formed the Network Resilience Coalition, a new alliance focused on securing data and networks that support global economic and national security. Its key aim is to help improve network hardware and software resilience on a global scale, bringing together infrastructure vendors/major network operators experienced in deploying […]
newswww.csoonline.comJul 25, 2023, 3:00 PMThe number of organizations vulnerable to data leaks because of security vulnerabilities in MOVEit Transfer software has dropped significantly with at least 77% of the initially affected organizations no longer susceptible, according to research by Bitsight. Progress, the developer of MOVEit, published an advisory alerting of a critical vulnerability in its MOVEit Transfer product on […]
newswww.csoonline.comJul 24, 2023, 11:49 AMGen Digital, which owns Avast, Avira, AVG, Norton, and LifeLock, said employee data was compromised in the MOVEit ransomware attack.
newswww.securityweek.comJun 20, 2023, 3:48 PM- A third MOVEit vulnerability fixed, Cl0p lists victim organizations (CVE-2023-35708)Help Net Security
Progress Software has asked customers to update their MOVEit Transfer installations again, to fix a third SQL injection vulnerability (CVE-2023-35708) discovered in the web application in less that a month. Previously, the Cl0p cyber extortion gang exploited CVE-2023-34362 to grab enterprise data, and Huntress researchers discovered CVE-2023-35036 after partnering with Progress to perform a code review of the web app. About CVE-2023-35708 CVE-2023-35708 is a vulnerability that could lead to escalated privileges and unauthorized access. … More →
newswww.helpnetsecurity.comJun 19, 2023, 11:56 AM A critical vulnerability (CVE-2023-35708) in MOVEit software could allow unauthenticated attackers to access database content.
newswww.securityweek.comJun 19, 2023, 10:52 AM- Progress fixed a third flaw in MOVEit Transfer softwareSecurity Affairs
Progress Software addressed a third vulnerability impacting its MOVEit Transfer application that could lead to privilege escalation and information disclosure. Progress Software disclosed a new SQL injection vulnerability impacting its MOVEit Transfer application, it is the third issue fixed by the company after: “Progress has discovered a vulnerability in MOVEit Transfer that could lead to escalated privileges […]
newssecurityaffairs.comJun 16, 2023, 10:55 AM The Cl0p ransomware gang has listed more than two dozen victims of the MOVEit zero-day attack on its leak website.
newswww.securityweek.comJun 16, 2023, 8:34 AMThe developer of the recently exploited MOVEit Transfer application issued new updates after a third-party security audit identified additional SQL injection vulnerabilities. Customers are advised to deploy the new patches as soon as possible since attackers are clearly interested in exploiting this and other enterprise secure file transfer solutions. “In addition to the ongoing investigation […]
newswww.csoonline.comJun 13, 2023, 5:50 PMAs more victim organizations of Cl0p gang’s MOVEit rampage continue popping up, security researchers have released a PoC exploit for CVE-2023-34362, the RCE vulnerability exploited by the Cl0p cyber extortion group to plunder confidential data. CVE-2023-34362 PoC exploit released Horizon3 security researchers have released proof-of-concept (PoC) exploit code for CVE-2023-34362, as well as technical root cause analysis of the flaw. Rapid7 has released an analysis of the vulnerability and a full exploit chain for CVE-2023-34362. … More →
newswww.helpnetsecurity.comJun 13, 2023, 11:17 AMResearchers discover new MOVEit vulnerabilities related to the zero-day, just as more organizations hit by the attack are coming forward.
newswww.securityweek.comJun 12, 2023, 10:26 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-42660CVSS 8.8 · High
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…
- CVE-2023-40043CVSS 7.2 · High
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…
- CVE-2023-36934CVSS 9.1 · Critical
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerab…
- CVE-2023-36932CVSS 8.1 · High
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection v…
- CVE-2023-35708CVSS 9.8 · Critical
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identi…
- CVE-2023-34362CVSS 9.8 · Critical
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found…