CVE-2023-34362: MOVEit Transfer SQL Injection
A SQL injection vulnerability in Progress Software's MOVEit Transfer managed file transfer application that lets an unauthenticated attacker access and modify the underlying database, then escalate to remote code execution. The Cl0p ransomware group exploited it as a zero-day to exfiltrate data from thousands of organizations in mid-2023.
View the authoritative record on NVD ↗Affected software
- MOVEit Transfer before 2021.0.6 (13.0.6)
- before 2021.1.4 (13.1.4)
- before 2022.0.4 (14.0.4)
- before 2022.1.5 (14.1.5)
- before 2023.0.1 (15.0.1)
How it's exploited
Send a crafted HTTP request to a MOVEit Transfer endpoint containing SQL injection payloads that grant unauthenticated database access, then use that access to upload a webshell and execute commands on the underlying server.
Severity
CVE-2023-34362 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2023-34362 is categorized under CWE-89, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for SQL Injection using Nuclei and OWASP ZAP, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 14 dedicated rules for this weakness.
Tools: Nuclei, OWASP ZAP
- SQL Injection Tainted Input
- SQL String Concatenation
- SQL Injection String Build
- SQL Injection Tainted Input
- SQL String Concatenation
- SQL Injection String Concatenation
- SQL Injection Tainted Input
- Laravel Raw SQL Injection
- SQL Injection Mysqli
- SQL Injection String Interpolation
- Django Raw SQL Injection
- SQL Injection Cursor Execute
Remediation
Apply the Progress Software patch for the affected version, rotate all MOVEit-related credentials and keys, and follow Progress's incident-response guidance to check for webshells left by mass exploitation.
Frequently asked questions
What is CVE-2023-34362?
A SQL injection vulnerability in Progress Software's MOVEit Transfer managed file transfer application that lets an unauthenticated attacker access and modify the underlying database, then escalate to remote code execution. The Cl0p ransomware group exploited it as a zero-day to exfiltrate data from thousands of organizations in mid-2023.
How severe is CVE-2023-34362?
CVE-2023-34362 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2023-34362?
CVE-2023-34362 affects MOVEit Transfer before 2021.0.6 (13.0.6); before 2021.1.4 (13.1.4); before 2022.0.4 (14.0.4); before 2022.1.5 (14.1.5); before 2023.0.1 (15.0.1).
How do you fix CVE-2023-34362?
Apply the Progress Software patch for the affected version, rotate all MOVEit-related credentials and keys, and follow Progress's incident-response guidance to check for webshells left by mass exploitation.
Where is the authoritative record for CVE-2023-34362?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2023-34362 at https://nvd.nist.gov/vuln/detail/CVE-2023-34362, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest