Skip to main content

CVE detail

CVE-2023-36932

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

CVSS 8.1 · HighBuzz score 32.5

Buzz score

Why this CVE is surfacing

Buzz score total 32.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
13.0
4 sources across 2 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Progress Software could be staring at fresh litigation over the explosive zero-day found in its file-transfer service, MOVEit, which affected millions of end users globally. The latest probe comes from the US Security and Exchange Commission (SEC), which is seeking information related to the mass hack. “On October 2, 2023, Progress received a subpoena from […]

    newswww.csoonline.comOct 12, 2023, 11:43 AM
  • This threat brief details the critical vulnerability CVE-2023-34362 found in MOVEit Transfer and includes Unit 42's observations, the current attack scope and interim guidance.

    vendorunit42.paloaltonetworks.comOct 4, 2023, 1:00 PM
  • Industry leaders across cybersecurity, networking, and service providers have formed the Network Resilience Coalition, a new alliance focused on securing data and networks that support global economic and national security. Its key aim is to help improve network hardware and software resilience on a global scale, bringing together infrastructure vendors/major network operators experienced in deploying […]

    newswww.csoonline.comJul 25, 2023, 3:00 PM
  • The number of organizations vulnerable to data leaks because of security vulnerabilities in MOVEit Transfer software has dropped significantly with at least 77% of the initially affected organizations no longer susceptible, according to research by Bitsight. Progress, the developer of MOVEit, published an advisory alerting of a critical vulnerability in its MOVEit Transfer product on […]

    newswww.csoonline.comJul 24, 2023, 11:49 AM
  • Progress released security patches for a new critical SQL injection vulnerability affecting its MOVEit Transfer software. Progress is informing customers of a new critical SQL injection vulnerability, tracked as CVE-2023-36934, in its MOVEit Transfer software. MOVEit Transfer software recently made the headlines due to the massive Clop ransomware hacking campaign exploiting a vulnerability in the […]

    newssecurityaffairs.comJul 7, 2023, 4:49 PM
  • Facing ransomware zero-days, Progress Software will release regular service packs to help customers mitigate critical security flaws.

    newswww.securityweek.comJul 7, 2023, 4:02 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2023-42660

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…

    CVSS 8.8 · High
  • CVE-2023-40043

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified…

    CVSS 7.2 · High
  • CVE-2023-36934

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerab…

    CVSS 9.1 · Critical
    7 mentions
  • CVE-2023-35708

    In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identi…

    CVSS 9.8 · Critical
    11 mentions
  • CVE-2023-35036

    In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found…

    CVSS 9.1 · Critical
    13 mentions
  • CVE-2023-34362

    In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found…

    CVSS 9.8 · Critical
    KEV listed75 mentions