Progress MOVEit Transfer
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*
- <= 2024.1.8
- >= 2025.0.0, <= 2025.0.7
- >= 2025.1.0, <= 2025.1.3
- 2026.0.0
A stored cross-site scripting vulnerability has been identified in the Ad Hoc module of Progress MOVEit Transfer. This issue allows an authenticated attacker to send a message containing a crafted JavaScript payload, which is then executed in the browser of the message recipient. The vulnerability affects MOVEit Transfer versions 2026.0.0 prior to 2026.0.1, 2025.1.0 prior to 2025.1.4, 2025.0.0 prior to 2025.0.8, and 2024.1.8 and earlier.
Exploitation of this vulnerability could lead to the execution of malicious scripts in the context of the user's browser, potentially allowing for session hijacking or other malicious actions.
Users are advised to upgrade to MOVEit Transfer versions 2026.0.1, 2025.1.4, or 2025.0.8. For those on MOVEit Cloud, no action is required as the environment has already been updated to a patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.