Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
References
Configurations
Configuration 1 (hide)
|
History
24 Nov 2025, 14:58
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Progress moveit Transfer
Progress |
|
| References | () https://docs.progress.com/bundle/moveit-transfer-release-notes-2024/page/Fixed-Issues-in-2024.1.8.html - Release Notes | |
| References | () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025/page/Fixed-Issues-in-2025.0.4.html - Release Notes | |
| References | () https://docs.progress.com/bundle/moveit-transfer-release-notes-2025_1/page/Fixed-Issues-in-2025.1.html - Release Notes | |
| CPE | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
19 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 21:15
Updated : 2025-11-24 14:58
NVD link : CVE-2025-13147
Mitre link : CVE-2025-13147
CVE.ORG link : CVE-2025-13147
JSON object : View
Products Affected
progress
- moveit_transfer
CWE
CWE-918
Server-Side Request Forgery (SSRF)
