Vulnerability record · CVE-2023-45727 · published 18 October 2023
CVE-2023-45727: Proself XXE flaw allows unauthenticated file read
Northgrid · Proself
Proself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote unauthenticated attacker can submit crafted XML to read arbitrary server files, including files containing account information. The flaw is rated CVSS 7.5 (HIGH) and has been added to CISA KEV, so it warrants prompt attention.
Description
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication or interaction required and confirmed inclusion in CISA KEV make this a high-priority patch target.
What it is
Proself Enterprise/Standard, Gateway, and Mail Sanitize editions fail to restrict XML external entities when parsing malformed XML requests. A remote unauthenticated attacker can submit crafted XML to read arbitrary server files, including files containing account information. The flaw is rated CVSS 7.5 (HIGH) and has been added to CISA KEV, so it warrants prompt attention.
Impact
An attacker gains read access to arbitrary files on the server, including account information, which can enable credential theft and follow-on access. No integrity or availability impact is described.
Attack surface
Reachable over the network via a specially crafted XML request; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
CISA added this to the KEV catalog on 2024-12-03 with a remediation due date of 2024-12-24, indicating known exploitation; EPSS 30-day probability is about 3.5 percent (88th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor fix from Proself (see vendor advisory) or upgrade to a version later than the affected releases.
- If no patch is available, discontinue use of the product as directed by CISA.
- Disable external entity and DTD processing in the XML parser where configuration allows.
- Restrict outbound network access from the Proself server to limit XXE data exfiltration.
- Limit file system permissions for the Proself service account to reduce what can be read.
Detection
- Monitor Proself/application logs for malformed XML requests or requests containing DOCTYPE or ENTITY declarations.
- Alert on outbound connections from the Proself server to unexpected hosts, which may indicate XXE exfiltration.
- Review file access by the Proself service account for reads of account or configuration files outside normal operation.
- Search web/proxy logs for XML POST bodies with external entity patterns targeting Proself endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-45727 to the Known Exploited Vulnerabilities catalog on 3 December 2024 as "North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN95981460/ | Third Party Advisory |
| https://www.proself.jp/information/153/ | Vendor Advisory |
| https://jvn.jp/en/jp/JVN95981460/ | Third Party Advisory |
| https://www.proself.jp/information/153/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-45727 | US Government Resource |
Track CVE-2023-45727 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-45727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.