CVE-2023-42660
Estado: ModificadaAlta (8.8)—
In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.70%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-89
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-42660",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-42660",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-26T21:51:01.378999Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@progress.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@progress.com",
"affectedData": [
{
"vendor": "Progress Software Corporation",
"modules": [
"MOVEit Transfer Machine Interface"
],
"product": "MOVEit Transfer",
"versions": [
{
"status": "affected",
"version": "2023.0.0 (15.0.0)",
"lessThan": "2023.0.6 (15.0.6)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2022.1.0 (14.1.0)",
"lessThan": "2022.1.9 (14.1.9)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2022.0.0 (14.0.0)",
"lessThan": "2022.0.8 (14.0.8)",
"versionType": "semver"
},
{
"status": "affected",
"version": "2021.1.0 (13.1.0)",
"lessThan": "2021.1.8 (13.1.8)",
"versionType": "semver"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2023-09-20T17:15:11.550",
"references": [
{
"url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023",
"tags": [
"Vendor Advisory"
],
"source": "security@progress.com"
},
{
"url": "https://www.progress.com/moveit",
"tags": [
"Product"
],
"source": "security@progress.com"
},
{
"url": "https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.progress.com/moveit",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@progress.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\nIn Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to the MOVEit Transfer machine interface which could result in modification and disclosure of MOVEit database content.\n\n"
},
{
"lang": "es",
"value": "En las versiones de MOVEit Transfer lanzadas antes de 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), se ha identificado una vulnerabilidad de inyección SQL en la interfaz de la máquina MOVEit Transfer que podría permitir que un atacante autenticado obtenga acceso no autorizado a la base de datos de MOVEit Transfer. Un atacante podría enviar un payload manipulado a la interfaz de la máquina MOVEit Transfer, lo que podría provocar la modificación y divulgación del contenido de la base de datos de MOVEit.\n"
}
],
"lastModified": "2026-06-17T06:24:12.277",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6E9F262-3E55-48FF-94A0-09C0C80FE7C0",
"versionEndExcluding": "2021.1.8"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1FFF5B1-D887-48EA-BFD1-FBD9F699DEA3",
"versionEndExcluding": "2022.0.8",
"versionStartIncluding": "2022.0.0"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "64138C94-BAB8-45D2-93A1-31FC4D4F1E41",
"versionEndExcluding": "2022.1.9",
"versionStartIncluding": "2022.1.0"
},
{
"criteria": "cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C35AF1A0-05E8-4F69-9F99-91925C490EE9",
"versionEndExcluding": "2023.0.6",
"versionStartIncluding": "2023.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@progress.com"
}