AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-6217

HIGH · CVSS 7.1 EPSS 0.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-11-29 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.1. It affects Java.

CVE
CVE-2023-6217
Severity
HIGH
CVSS
7.1
EPSS
0.51%
Java

Original NVD Description

In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer.  An attacker could craft a malicious payload targeting the system which comprises a MOVEit Gateway and MOVEit Transfer deployment. If a MOVEit user interacts with the crafted payload, the attacker would be able to execute malicious JavaScript within the context of the victim’s browser.

Related CVEs

Other vulnerabilities affecting the same vendor(s)