Executive brief
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize editions contain an XML External Entity (XXE) vulnerability. A remote, unauthenticated attacker can send a specially crafted XML request to read arbitrary files on the server, potentially exposing sensitive account information.
Affected products
- North Grid Proself Enterprise Edition Ver5.62 and earlier
- North Grid Proself Standard Edition Ver5.62 and earlier
- North Grid Proself Gateway Edition Ver1.65 and earlier
- North Grid Proself Mail Sanitize Edition Ver1.08 and earlier
Timeline
- 2023-10-18: disclosed: NVD Published Date
- 2024-12-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-12-24: other: CISA KEV remediation due date