VYPR
Medium severity6.5NVD Advisory· Published Feb 10, 2016· Updated Jun 17, 2026

CVE-2015-7675

CVE-2015-7675

Description

The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Ipswitch, Inc./Moveit Dmzllm-fuzzy2 versions
    <8.2+ 1 more
    • (no CPE)range: <8.2
    • cpe:2.3:a:ipswitch:moveit_dmz:*:*:*:*:*:*:*:*range: <=8.1
  • Ipswitch, Inc./Moveit Mobilellm-fuzzy2 versions
    <1.2.2+ 1 more
    • (no CPE)range: <1.2.2
    • cpe:2.3:a:ipswitch:moveit_mobile:*:*:*:*:*:*:*:*range: <=1.2.0.962

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.