MOVEit Transfer Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-8612
In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1 a REST API endpoint failed to adequately sanitize malicious input which could allow an authenticated attacker to execute arbitrary code in a victim39s browser aka XSS.