Critical severity9.0NVD Advisory· Published Feb 14, 2020· Updated Jun 17, 2026
CVE-2020-8612
CVE-2020-8612
Description
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*range: >=2019.2,<2019.2.1
- (no CPE)range: <2019.1.4, <2019.2.1
- Progress/MOVEit Transferdescription
Patches
Vulnerability mechanics
References
4- community.ipswitch.com/s/article/MOVEit-Transfer-Security-Vulnerabilities-Feb-2020nvdPatchVendor Advisory
- docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htmnvdRelease NotesVendor Advisory
- docs.ipswitch.com/MOVEit/Transfer2019_2/ReleaseNotes/en/index.htmnvdRelease NotesVendor Advisory
- status.moveitcloud.comnvdProduct
News mentions
0No linked articles in our index yet.