CVE-2023-45727

Published Oct 18, 2023

Last updated 2 months ago

Overview

Description
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
Source
vultures@jpcert.or.jp
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
Exploit added on
Dec 3, 2024
Exploit action due
Dec 24, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
CWE-611
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-611

Social media

Hype score
Not currently trending
  1. #DOYOUKNOWCVE CISA Alert! Last week 4 critical vulnerabilities were added to the CISA KEV Catalog! These vulnerabilities highlight the importance of staying updated with patches and safeguarding systems. 🔹 CVE-2023-45727 (North Grid Proself): A critical flaw due to improper… h

    @Loginsoft_Inc

    10 Dec 2024

    49 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA Warns of Exploitation of Flaws in ProjectSend, CyberPanel, and Zyxel: CVE-2024-51378 CVE-2023-45727 CVE-2024-11680 CVE-2024-11667 CVE-2024-45841 CVE-2024-47133 CVE-2024-52564 https://t.co/qerETOTK91

    @vault33org

    5 Dec 2024

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-11667 is getting exploited #inthewild. Find out more at https://t.co/3DJJRw40Uh CVE-2024-11680 is getting exploited #inthewild. Find out more at https://t.co/fRRrITY2ke CVE-2023-45727 is getting exploited #inthewild. Find out more at https://t.co/qiH2XzNI4L

    @inthewildio

    4 Dec 2024

    106 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2023-45727 North Grid Proself Improper Restriction of XML External Entity (XEE) Reference Vulnerability CVE-2024-11680 ProjectSend Improper… htt

    @johnmstark

    3 Dec 2024

    55 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-45727 North Grid #Proself Improper Restriction of XML External Entity (XEE) Reference Vulnerability https://t.co/JTzNfnkbtx

    @ScyScan

    3 Dec 2024

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA Adds Three Known Exploited Vulnerabilities to Catalog: CVE-2024-11667 - Zyxel Multiple Firewalls Path Traversal CVE-2024-11680 - ProjectSend Improper Authentication CVE-2023-45727 - North Grid Proself Improper Restriction of XML External Entity (XEE) Reference… https://t.co/

    @TMJIntel

    3 Dec 2024

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations