CVE-2023-45727
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 December 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.54% probability · 89th percentile
- CISA KEV
- Listed 3 December 2024 · due 24 December 2024
- Weakness
- CWE-611
- Affected
- northgrid/proself
- Source
- vultures@jpcert.or.jp
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.proself.jp/information/153/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-45727
References
- https://jvn.jp/en/jp/JVN95981460/Third Party Advisory
- https://www.proself.jp/information/153/Vendor Advisory
- https://jvn.jp/en/jp/JVN95981460/Third Party Advisory
- https://www.proself.jp/information/153/Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45727US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.