CVE-2025-11235 | Progress MOVEit Transfer up to 2022.0.9/2022.1.10/2023.0.7/2023.1.2 on Windows REST API unverified password change (EUVD-2025-206248 / WID-SEC-2026-0042)
A vulnerability categorized as problematic has been discovered in Progress MOVEit Transfer up to 2022.0.9/2022.1.10/2023.0.7/2023.1.2 on Windows. The affected element is an unknown function of the component REST API Module. The manipulation results in unverified password change.
This vulnerability is cataloged as CVE-2025-11235. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.