CVE-2020-28647

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

Information

Published : 2020-11-17 06:15

Updated : 2022-10-21 12:32


NVD link : CVE-2020-28647

Mitre link : CVE-2020-28647


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

progress

  • moveit_transfer