← Vulnerability feed

Vulnerability record · CVE-2023-45727 · published 18 October 2023

CVE-2023-45727: Proself XXE flaw allows unauthenticated file read

Northgrid · Proself

Proself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote unauthenticated attacker can submit crafted XML to read arbitrary server files, including files containing account information. The flaw is rated CVSS 7.5 (HIGH) and has been added to CISA KEV, so it warrants prompt attention.

7.5 CVSS 3.1 High CISA KEV since 3 Dec 2024 EPSS 3.5% · top 11.1% CWE-611 · XML external entity (XXE)
7.5CVSS 3.1 base score
3.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 7.5 with no authentication or interaction required and confirmed inclusion in CISA KEV make this a high-priority patch target.

What it is

Proself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote unauthenticated attacker can submit crafted XML to read arbitrary server files, including files containing account information. The flaw is rated CVSS 7.5 (HIGH) and has been added to CISA KEV, so it warrants prompt attention.

Impact

An attacker gains read access to arbitrary files on the server, including account information, which can enable credential theft and follow-on access. No integrity or availability impact is described.

Attack surface

Reachable over the network via a specially crafted XML request; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

CISA added this to the KEV catalog on 2024-12-03 with a remediation due date of 2024-12-24, indicating known exploitation; EPSS 30-day probability is about 3.5 percent (88th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor fix from Proself (see vendor advisory) or upgrade to a version later than the affected releases.
  • If no patch is available, discontinue use of the product as directed by CISA.
  • Disable external entity and DTD processing in the XML parser where configuration allows.
  • Restrict outbound network access from the Proself server to limit XXE data exfiltration.
  • Limit file system permissions for the Proself service account to reduce what can be read.

Detection

  • Monitor Proself/application logs for malformed XML requests or requests containing DOCTYPE or ENTITY declarations.
  • Alert on outbound connections from the Proself server to unexpected hosts, which may indicate XXE exfiltration.
  • Review file access by the Proself service account for reads of account or configuration files outside normal operation.
  • Search web/proxy logs for XML POST bodies with external entity patterns targeting Proself endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-45727 to the Known Exploited Vulnerabilities catalog on 3 December 2024 as "North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-39415Northgrid proself improper authentication vulnerabilityImproper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Pr…EPSS 1.0%7.2CVE-2023-39416Northgrid proself os command injection vulnerabilityProself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and e…EPSS 1.2%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed9.8CVE-2024-34102Adobe Commerce and Magento XXE flaw allows unauthenticated code executionAdobe Commerce and Magento Open Source are affected by an improper restriction of XML external entity reference (XXE) vulnerability. A crafted XML do…KEVEPSS 100%analysed9.8CVE-2019-9670Zimbra mailboxd Autodiscover XXE allows unauthenticated compromiseThe mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 parses XML in the Autodiscover servlet without restricting extern…KEVEPSS 100%analysed7.5CVE-2019-13608Citrix StoreFront Server XXE allows unauthenticated file disclosureCitrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) is vulnerable to XML External Entity (XXE)…KEVEPSS 30%analysed

Source: NIST National Vulnerability Database (record CVE-2023-45727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.