S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-34362 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in MOVEit Transfer affects v. before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-34362
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
moveit_transferby progress
AFFECTED< 2020.0SAFE ✓≥ 2020.0
moveit_transferby progress
2020.1
moveit_transferby progress
AFFECTED< 2021.0.7SAFE ✓≥ 2021.0.7
Updated Aug 22, 2026View on NVD →
Detail

Moveit Transfer is a secure and reliable managed file transfer solution designed to allow businesses to send and receive sensitive data between different locations, systems, and partners. The product ensures that data is transferred quickly, accurately and with confidence, making it an ideal solution for businesses that require a compliant and auditable solution.

Recently, a severe vulnerability CVE-2023-34362 has been detected in Moveit Transfer before versions 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1). The vulnerability is classified as a SQL injection flaw in the Moveit Transfer web application, which can allow attackers to access the database and execute arbitrary SQL commands on the database. The vulnerability can also enable attackers to obtain confidential information from the database and gain unauthorized access to sensitive data on the system.

When this vulnerability is exploited, an attacker can gain access to sensitive data such as usernames, passwords, transaction details, and other confidential information. In addition, the attacker can also manipulate or modify the database, which can lead to severe consequences such as data loss, system failure, and business disruption. Once attackers gain access to sensitive data, they can use it for cybercrime activities, which may include identity theft, ransomware, and fraud.

In conclusion, it is essential to stay informed about vulnerabilities and take proactive measures to protect digital assets. With the pro features of the s4e.io platform, individuals and businesses can keep their systems safe and secure from various threats. It is important always to keep software and systems up to date to avoid potential vulnerabilities, and regularly conduct security audits to ensure that security measures are up to standard.

 

REFERENCES

Solution Advice

To prevent this vulnerability from being exploited, there are several precautions that users can take, including the following:

  • Update to the latest version of Moveit Transfer, which contains the necessary patches to fix the vulnerability.
  • Restrict user access to the Moveit Transfer application and ensure that only authorized users have access to the system.
  • Implement network segmentation to prevent unauthorized access to the system.
  • Deploy a security solution that includes antivirus, firewalls, and intrusion detection systems to monitor and detect any malicious activity.
  • Regularly test for vulnerabilities and perform penetration testing to identify and address vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-34362 scanner - SQL Injection (SQLi) vulnerability in MOVEit Transfer S4E