CVE-2025-11235

Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

History

03 Feb 2026, 16:54

Type Values Removed Values Added
First Time Progress moveit Transfer
Progress
CPE cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
References () https://docs.progress.com/bundle/moveit-transfer-release-notes-2023_1/page/Fixed-Issues-in-2023.1.3.html - () https://docs.progress.com/bundle/moveit-transfer-release-notes-2023_1/page/Fixed-Issues-in-2023.1.3.html - Release Notes

Information

Published : 2026-01-07 12:16

Updated : 2026-02-03 16:54


NVD link : CVE-2025-11235

Mitre link : CVE-2025-11235

CVE.ORG link : CVE-2025-11235


JSON object : View

Products Affected

progress

  • moveit_transfer
CWE
CWE-620

Unverified Password Change