Title: Missing Server-Side Input Validation leads to computational errors and potential denial of service in Progress MOVEit Transfer
CVE ID: CVE-2024-0396
CVSSv3 Base Score: 7.1 (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H)
Vendor: Progress Software Corporation (Progress)
Products: Progress MOVEit Transfer
Advisory Release Date: 18-01-2024
Advisory URL: https://labs.integrity.pt/advisories/cve-2024-0396
Credits: Discovery by Pedro Valadares Pinho <pedro.pinho[at]devoteam.com>
In Progress MOVEit Transfer an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within MOVEit Transfer and potentially result in a denial of service.
© 2024 INTEGRITY S.A. All rights reserved. | Cookie Policy