Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-36932
HistoryJul 05, 2023 - 4:15 p.m.

Sql injection

2023-07-0516:15:00
PRIOn knowledge base
www.prio-n.com
5
sql injection
moveit transfer
web application
vulnerability
authenticated attacker
unauthorized access
database modification
disclosure

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

Related for PRION:CVE-2023-36932