3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Description
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
Basic Information
ID
CVE-2025-11235
Source
ProgressSoftware
Published
Jan 6, 2026 at 22:16
Affected Product
Vendor
Progress
Product
MOVEit Transfer
Version
2023.1.0
Affected Versions
Progress MOVEit Transfer 2023.1.0
Progress MOVEit Transfer 2023.0.0
Progress MOVEit Transfer 2022.1.0
Progress MOVEit Transfer 2022.0.0
Progress MOVEit Transfer 2023.0.0
Progress MOVEit Transfer 2022.1.0
Progress MOVEit Transfer 2022.0.0