VYPR
Low severity3.7NVD Advisory· Published Jan 7, 2026· Updated Jun 17, 2026

CVE-2025-11235

CVE-2025-11235

Description

Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.

Affected products

3
  • 2023.1.0+ 2 more
    • (no CPE)range: 2023.1.0
    • (no CPE)range: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10
    • cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*range: >=2022.0.0,<2022.0.10

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.