CVE-2023-45727
HIGH KEVNorthgrid Proself < 1.09 - XXE
Title source: ruleDescription
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
Scores
CVSS v3
7.5
EPSS
0.2105
EPSS Percentile
95.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CISA KEV
2024-12-03
VulnCheck KEV
2024-09-13
InTheWild.io
2024-12-03
ENISA EUVD
EUVD-2023-50016
CWE
CWE-611
Status
published
Products (3)
northgrid/proself
< 1.09
northgrid/proself
< 1.66
northgrid/proself
< 5.63 (2 CPE variants)
Published
Oct 18, 2023
KEV Added
Dec 03, 2024
Tracked Since
Feb 18, 2026