CRITICAL
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS
Published Feb 14, 2020
9.0
CRITICALCVSS 3.1
EPSS 1.67%
Description
Affected products
Remediation
References (5)
Change history (0)
No recorded changes yet.