Impact
The flaw in MOVEit Transfer’s file upload modules is a CWE‑46 weakness that allows a file extension restriction bypass by exploiting path equivalence. An attacker can craft file names to upload malicious content be placed on the system and potentially compromising integrity.
Affected Systems
Progress MOVEit Transfer versions prior to 2025.0.8 and between 2025.1.0 and before 2025.1.4 are affected. Any environment running one of those releases is potentially vulnerable.
Risk and Exploitability
Based on the description, the exploit likely occurs through the web upload interface, a vector that is externally reachable and requires only user interaction. With a CVSS score of 3.5 the issue rates as low severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. While the exploit conditions are straightforward, the low severity and lack of widespread exploitation evidence suggest this vulnerability is not an immediate threat, is advisable.
OpenCVE Enrichment