PT-2020-17024 · Ipswitch · Moveit Transfer

Mark Galea

·

Published

2020-11-17

·

Updated

2022-10-21

·

CVE-2020-28647

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MOVEit Transfer versions prior to 2020.1
Description A malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser, resulting in a cross-site scripting (XSS) attack.
Recommendations For versions prior to 2020.1, update to version 2020.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the application to minimize the risk of exploitation. Avoid interacting with potentially malicious payloads within the MOVEit Transfer instance until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-28647

Affected Products

Moveit Transfer