Skip to main content
Mallory
Critical

SQL Injection in Progress MOVEit Transfer

IdentifiersCVE-2023-35036CWE-89· Improper Neutralization of Special…

CVE-2023-35036 is a critical SQL injection vulnerability in the Progress MOVEit Transfer web application. According to the provided content, affected versions are MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), with a special patch for 2020.1.x and older unsupported branches requiring upgrade. The flaw allows an unauthenticated attacker to submit a crafted payload to a MOVEit Transfer application endpoint, resulting in unauthorized access to the MOVEit database. Successful exploitation can lead to modification and disclosure of database content. The issue was disclosed on 2023-06-09 during additional code review and security audit activity following the earlier MOVEit zero-day incident.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows unauthorized database access without authentication. An attacker can disclose MOVEit database contents and modify stored data, compromising confidentiality and integrity. The provided content also characterizes the issue as critical and remotely exploitable over the network with no user interaction, and CVSS material in the content indicates high impact to confidentiality, integrity, and availability. On internet-exposed MOVEit Transfer systems, this could facilitate broader compromise of the application environment, theft of sensitive managed file transfer metadata or related records, and follow-on exploitation depending on deployment specifics.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce or remove web exposure of MOVEit Transfer. The provided content recommends temporarily blocking HTTP/HTTPS access and relying on unaffected transfer methods where operationally feasible, and placing MOVEit Transfer behind a firewall, VPN, or SSO landing page to limit direct internet reachability. Because this vulnerability was disclosed amid active exploitation of related MOVEit flaws, organizations should also review for indicators of compromise, investigate unauthorized access, and rotate relevant database credentials and cloud/storage keys if compromise is suspected and such integrations are configured.

Remediation

Patch, then assume compromise.

Upgrade MOVEit Transfer to a fixed version released by Progress. The provided content identifies fixed versions as 2021.0.7, 2021.1.5, 2022.0.5, 2022.1.6, and 2023.0.2. For MOVEit Transfer 2020.1.x, apply the vendor-provided special patch. For 2020.0.x or older, upgrade to a supported version. The content also states that MOVEit Cloud clusters were patched by Progress. Apply only vendor-issued updates and follow Progress advisory guidance for post-patch validation.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Progress SoftwareMoveit Transferapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware4

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.