References https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/ https://www.huntress.com/blog/moveit-transfer-critical-vulnerability-rapid-response https://zeropath.com/blog/cve-2023-34362-moveit-transfer-sql-injection-exploitation https://www.assetnote.io/resources/research/moveit-transfer-rce-part-two-cve-2023-34362/ https://nvd.nist.gov/vuln/detail/cve-2023-34362 https://www.fastly.com/blog/cve-2023-34362-progress-moveit-transfer-sql-injection-vulnerability https://bbs.kanxue.com/thread-277841.htm https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023 https://www.akamai.com/blog/security-research/moveit-sqli-zero-day-exploit-clop-ransomware https://horizon3.ai/attack-research/attack-blogs/moveit-transfer-cve-2023-34362-deep-dive-and-indicators-of-compromise/
Related VulnerabilitiesPoCCVE-2026-8037: Progress ADC LoadMaster - Command InjectionProgress Kemp LoadMaster /accessv2 命令执行漏洞(CVE-2026-8037)Progress WhatsUp Gold /NmConsole/Platform/PerformanceMonitorErrors/HasErrors SQL 注入漏洞(CVE-2024-6670)Evertz SDVN /v.1.5/php/features/feature-transfer-export.php 命令执行漏洞(CVE-2025-4009)PoCCVE-2026-2699: Progress ShareFile Storage Zones Controller - Authentication BypassProgress ShareFile Storage Zones Controller /ConfigService/Admin.aspx 权限绕过漏洞(CVE-2026-2699)PoCCVE-2023-35708: MOVEit Transfer - SQL InjectionPoCCVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSSProgress Chef Automate /api/v0/compliance/profiles/search SQL 注入漏洞(CVE-2025-8868)PoC普华 PowerPMS Transfer.aspx 未授权访问漏洞Progress Telerik Report Server /Startup/Register 未授权访问漏洞(CVE-2024-4358)