Impact
The flaw is an Improper Neutralization of Special Elements in Data Query Logic in the Custom Reports module of Progress MOVEit Transfer. It allows a user who can create or execute custom reports to craft a query that references database tables outside the intended scope, potentially exposing sensitive data that should otherwise be inaccessible.
Affected Systems
The vulnerability affects Progress MOVEit Transfer versions prior to 2025.0.8 (including 2025.0.0 through 2025.0.7), prior to 2025.1.4 (including 2025.1.0 through 2025.1.3) and prior to 2026.0.1 (including 2026.0.0).
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate to high severity. With an EPSS score of less than 1 % the likelihood of exploitation is considered low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path requires an authenticated user with permission to create or run custom reports; such a user can construct a malicious report definition that retrieves data from tables outside the permitted scope. Successful exploitation would result in the disclosure of confidential information.
OpenCVE Enrichment