Junglewise Threat Intelligence

CVE-2023-45727: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

CVE-2023-45727 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-12-03

Executive brief

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize editions contain an XML External Entity (XXE) vulnerability. A remote, unauthenticated attacker can send a specially crafted XML request to read arbitrary files on the server, potentially exposing sensitive account information.

Affected products

  • North Grid Proself Enterprise Edition Ver5.62 and earlier
  • North Grid Proself Standard Edition Ver5.62 and earlier
  • North Grid Proself Gateway Edition Ver1.65 and earlier
  • North Grid Proself Mail Sanitize Edition Ver1.08 and earlier

Timeline

  • 2023-10-18: disclosed: NVD Published Date
  • 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-24: other: CISA KEV remediation due date