Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Moveit_transfer | Progress | 2022.0.0 (including) | 2022.0.10 (excluding) |
| Moveit_transfer | Progress | 2022.1.0 (including) | 2022.1.11 (excluding) |
| Moveit_transfer | Progress | 2023.0.0 (including) | 2023.0.8 (excluding) |
| Moveit_transfer | Progress | 2023.1.0 (including) | 2023.1.3 (excluding) |