Sploitus

CVE-2023-34362

30 known exploits for CVE-2023-34362

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database, and execute SQL statements that alter or delete database elements. NOTE: this is exploited in the wild in May and June 2023; exploitation of unpatched systems can occur via HTTP or HTTPS. All versions (e.g., 2020.0 and 2019x) before the five explicitly mentioned versions are affected, including older unsupported versions.

Affected products
Moveit Transfer
Progress Moveit Cloud
< 14.0.5.45, 14.1.6.97, 15.0.2.39
Progress Moveit Transfer
< 2021.0.7, 2021.1.5, 2022.0.5, 2022.1.6, 2023.0.2
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
99.9% (100th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2023-06-02
CVE-2023-34362 at NVD
Authoritative description, scoring and affected products

30 known exploits for CVE-2023-34362

Proof-of-concept code and exploit modules indexed by Sploitus

CVE-2023-26067
2026-09-05 KitPloitKITPLOIT
MOVEit-CVE-2023-34362
2026-09-05 KitPloitKITPLOIT
MoveIT-CVE-2023-34362-RCE
2026-09-05 KitPloitKITPLOIT
MOVEit_CVE-2023-34362_IOCs
2026-09-05 KitPloitKITPLOIT
MOVEit-Exploit
2026-09-05 KitPloitKITPLOIT
MOVEit-CVE-2023-34362
2026-09-05 KitPloitKITPLOIT
CVE-2023-34362
2026-09-05 KitPloitKITPLOIT
MOVEit-Transfer-Data-Breach-Analysis.
2026-09-04 KitPloitKITPLOIT
MOVEit-CVE-2023-34362
2026-09-03 KitPloitKITPLOIT
moveit-payload-decrypt-CVE-2023-34362
2026-09-02 KitPloitKITPLOIT
CVE-2023-34362
2026-09-02 KitPloitKITPLOIT
moveit-transfer-cve-2023-34362
2026-09-02 KitPloitKITPLOIT
moveit-transfer-2023-breach
2026-09-01 KitPloitKITPLOIT
CVE-2023-34362
2026-09-01 KitPloitKITPLOIT
Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer
2026-08-31 KitPloitKITPLOIT
CVE-2023-34362-Defense-Package
2026-08-30 KitPloitKITPLOIT
Exploit for SQL Injection in Progress Moveit_Cloud
2026-06-06 horristerGITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2026-05-06 KarmanyaT28GITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2026-01-21 khengar9274-webGITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2025-07-28 Naveenbana5250GITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2024-06-28 glen-pearsonGITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2023-08-31 errorfiathckGITHUB
Exploit for Improper Input Validation in Lexmark Cxtpc_Firmware
2023-08-07 horizon3aiGITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2023-07-09 Malwareman007GITHUB
MOVEit SQL Injection Exploit
2023-06-26 metasploitZDTRuby
MOVEit SQL Injection
2023-06-23 bwatters-r7, sfewer-r7, rbowes-r7, metasploit.comPACKETSTORMRuby
Exploit for SQL Injection in Progress Moveit_Cloud
2023-06-16 kenbucklerGITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2023-06-12 sfewer-r7GITHUB
Exploit for SQL Injection in Progress Moveit_Cloud
2023-06-09 horizon3aiGITHUB
MOVEit SQL Injection vulnerability
2023-05-31 sfewer-r7, rbowes-r7, bwatters-r7METASPLOITRuby