CVE-2025-13147

Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

History

24 Nov 2025, 14:58

Type Values Removed Values Added
First Time Progress moveit Transfer
Progress
References () https://docs.progress.com/bundle/moveit-transfer-release-notes-2024/page/Fixed-Issues-in-2024.1.8.html - () https://docs.progress.com/bundle/moveit-transfer-release-notes-2024/page/Fixed-Issues-in-2024.1.8.html - Release Notes
References () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025/page/Fixed-Issues-in-2025.0.4.html - () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025/page/Fixed-Issues-in-2025.0.4.html - Release Notes
References () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025_1/page/Fixed-Issues-in-2025.1.html - () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025_1/page/Fixed-Issues-in-2025.1.html - Release Notes
CPE cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

19 Nov 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 21:15

Updated : 2025-11-24 14:58


NVD link : CVE-2025-13147

Mitre link : CVE-2025-13147

CVE.ORG link : CVE-2025-13147


JSON object : View

Products Affected

progress

  • moveit_transfer
CWE
CWE-918

Server-Side Request Forgery (SSRF)