In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
| Software | From | Fixed in |
|---|---|---|
| progess / moveit_transfer | 2019.1 | 2019.1.4 |
| progress / moveit_transfer | 2019.2 | 2019.2.1 |