Impact
The vulnerability in Progress MOVEit Transfer arises from improper neutralization of special elements in the custom reports query logic. When a user submits a report request, the system fails to sanitize certain characters or tokens, allowing the attacker to modify the intended data scope. This flaw (CWE-943) effectively lets an authenticated user bypass institutional access controls and retrieve data that should be restricted, enabling unauthorized access to sensitive information. (The requirement for authentication is inferred from the data query context.)
Affected Systems
Progress MOVEit Transfer is affected in all releases prior to version 2025.0.7 and in the 2025.1.0‑2025.1.2 series. Administrators should verify that their environment is running a patched release such as 2025.1.3 or later.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium risk level, while the EPSS score is below 1% and the vulnerability has not been listed in the CISA KEV catalog, suggesting limited observed exploitation. The likely attack vector involves an authenticated user submitting a crafted report request to modify the data query. (Based on the description, it is inferred that the attacker requires access to the custom reports functionality.) No public exploitation evidence is currently known, but the potential for unauthorized data exfiltration warrants a moderate level of attention.
OpenCVE Enrichment