CVE-2023-34362
CWE-89
103.8
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 99.93%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Jun 2023
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-89
- Published
- 2 Jun 2023
- Last modified 27 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2023-34362Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time