Impact
The vulnerability arises from improper neutralization of user input during web Progress MOVEit Transfer, classified as a Stored XSS flaw (CWE‑79). An attacker who can submit malicious input that is later rendered in a victim’s browser could execute arbitrary scripts, potentially allowing session hijacking, theft of sensitive data, or other malicious actions that threaten confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected versions include all releases of Progress MOVEit Transfer before 2026.0.1, before 2025.1.4, and before 2025.0.8.
Risk and Exploitability
With a CVSS score of 8 the vulnerability is considered high risk, and the EPSS score of < 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is the web interface of the Ad‑Hoc module, where a user can submit content that is stored and later rendered to other users; no special privileges beyond module access are required.
OpenCVE Enrichment