vulnerability
Progress MOVEit Transfer: CVE-2020-8611: SQL Injection in MOVEit Transfer REST API
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | Apr 16, 2020 | Dec 13, 2024 | Dec 23, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
Apr 16, 2020
Added
Dec 13, 2024
Modified
Dec 23, 2025
Description
Multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer"s database.
Solution
progress-moveit-transfer-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.