CVE-2025-11235 Details
Description
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
A vulnerability allowing unverified password changes has been identified in Progress MOVEit Transfer on Windows, specifically within the REST API modules. This issue affects MOVEit Transfer versions 2023.1.0 prior to 2023.1.3, 2023.0.0 prior to 2023.0.8, 2022.1.0 prior to 2022.1.11, and 2022.0.0 prior to 2022.0.10.
Users can upgrade to MOVEit Transfer version 2023.1.3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.progress.com/bundle/moveit-transfer-release-notes-2023_1/page/Fixed-Issues-in-2023.1.3.html | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-620 | Unverified Password Change | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress moveit transfer | >= 2022.0.0, < 2022.0.10 >= 2022.1.0, < 2022.1.11 >= 2023.0.0, < 2023.0.8 >= 2023.1.0, < 2023.1.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | Initial Analysis | [email protected] |
| Jan 7, 2026 | New CVE Received | [email protected] |