CVE-2023-42656
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
20/09/2023
Last modified:
22/09/2023
Description
<br />
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer&#39;s web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users during the package composition procedure. If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victims browser.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | 2021.1.8 (excluding) | |
| cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | 2022.0.0 (including) | 2022.0.8 (excluding) |
| cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | 2022.1.0 (including) | 2022.1.9 (excluding) |
| cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | 2023.0.0 (including) | 2023.0.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



