Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
References
| Link | Resource |
|---|---|
| https://docs.progress.com/bundle/moveit-transfer-release-notes-2023_1/page/Fixed-Issues-in-2023.1.3.html | Release Notes |
Configurations
Configuration 1 (hide)
|
History
03 Feb 2026, 16:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Progress moveit Transfer
Progress |
|
| CPE | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | |
| References | () https://docs.progress.com/bundle/moveit-transfer-release-notes-2023_1/page/Fixed-Issues-in-2023.1.3.html - Release Notes |
Information
Published : 2026-01-07 12:16
Updated : 2026-02-03 16:54
NVD link : CVE-2025-11235
Mitre link : CVE-2025-11235
CVE.ORG link : CVE-2025-11235
JSON object : View
Products Affected
progress
- moveit_transfer
CWE
CWE-620
Unverified Password Change
