Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
Any version before 2024.1.8
affected
2025.0.0 (semver) before 2025.0.4
affected
Description
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
Any version before 2024.1.8
2025.0.0 (semver) before 2025.0.4
Credits
Early Warning Services
Michael McCambridge
Brian Tigges
Jason Scribner
Alex Achs
References
docs.progress.com/...2024/page/Fixed-Issues-in-2024.1.8.html
docs.progress.com/...2025/page/Fixed-Issues-in-2025.0.4.html
docs.progress.com/...2025_1/page/Fixed-Issues-in-2025.1.html