Executive brief
Progress MOVEit Transfer, a secure managed file transfer solution, contains a vulnerability in its Custom Reports module. This flaw could allow a high-privileged user to manipulate data queries, potentially leading to unauthorized access to sensitive information or unintended data modifications. Exploitation requires specific user interaction and high-level administrative access, limiting the immediate risk to most organizations.
Technical details
A vulnerability classified as Improper Neutralization of Special Elements in Data Query Logic (CWE-943) exists in the Custom Reports modules of Progress MOVEit Transfer. The flaw stems from insufficient validation of query parameters, which could allow an attacker to manipulate the logic of data queries. An exploit requires the attacker to have high-privileged (administrative) credentials and involves a high degree of complexity, including required user interaction. If successful, an attacker could potentially bypass intended scoping of report results to access or modify data across the system. The issue is resolved in versions 2025.0.7, 2025.1.3, and subsequent releases.
Affected products
- Progress MOVEit Transfer before 2025.0.7, 2025.1.0 before 2025.1.3
Timeline
- 2026-07-08: advisory: Initial disclosure by Progress Software and NVD publication