{ "schema_version": "1.4.0", "id": "GHSA-7q5w-gw6h-9g37", "modified": "2022-05-24T17:09:04Z", "published": "2022-05-24T17:09:04Z", "aliases": [ "CVE-2020-8612" ], "details": "In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8612" }, { "type": "WEB", "url": "https://community.ipswitch.com/s/article/MOVEit-Transfer-Security-Vulnerabilities-Feb-2020" }, { "type": "WEB", "url": "https://docs.ipswitch.com/MOVEit/Transfer2019_1/ReleaseNotes/en/index.htm#49443.htm" }, { "type": "WEB", "url": "https://docs.ipswitch.com/MOVEit/Transfer2019_2/ReleaseNotes/en/index.htm#49677.htm" }, { "type": "WEB", "url": "https://status.moveitcloud.com" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-02-14T19:15:00Z" } }