CVE-2023-45727

Confirmed PUBLISHED

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and...

North Grid Corporation · Proself Enterprise/Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High

At a Glance

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

cisa
CVE Published
Oct 18, 2023
Exploitation Reported
Dec 03, 2024
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
northgrid
proself

0 to <= 5.62

Affected
northgrid
proself

0 to <= 1.65

Affected
northgrid
proself

0 to <= 5.62

Affected
northgrid
proself

0 to <= 1.08

Affected
North Grid Corporation
Proself Enterprise/Standard Edition

Ver5.62 and earlier

Affected
North Grid Corporation
Proself Gateway Edition

Ver1.65 and earlier

Affected
North Grid Corporation
Proself Mail Sanitize Edition

Ver1.08 and earlier

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.