Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation in Progress MOVEit Transfer. An attacker who can inject malicious scripts into the application’s persistent data will cause those scripts to be executed in the browsers of other users who view the affected content. This can lead to session hijacking, credential theft, defacement, or other client‑side compromise. The weakness is catalogued as CWE‑79, indicating an input validation issue.
Affected Systems
The affected product is Progress MOVEit Transfer. All releases prior to 2025.1.5 and the 2026 range from 2026.0.0 up through (but not including) 2026.0.3 are vulnerable. All newer releases post‑2026.0.3 or the 2025.1.5+ iterations contain the fix.
Risk and Exploitability
The CVSS score of 7.1 categorises this as high severity. Its EPSS score is below 1 %, meaning the probability of exploitation at the current time is low but not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires a user to submit input that is stored by the application and later displayed to others, making the exploitation web‑based and user‑interaction dependent.
OpenCVE Enrichment