Sploitus

CVE-2020-28647

2 known exploits for CVE-2020-28647

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim's browser (XSS).

Affected products
Moveit Transfer
Progress Moveit Transfer
< 2020.1
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
1.5% (72th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2020-11-17
CVE-2020-28647 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2020-28647

Proof-of-concept code and exploit modules indexed by Sploitus