CVE-2023-45727 is an XML External Entity (XXE) vulnerability affecting Proself Enterprise/Standard Edition (v5.62 and earlier), Proself Gateway Edition (v1.65 and earlier), and Proself Mail Sanitize Edition (v1.08 and earlier). This high-severity vulnerability, rated 7.5 CVSS, allows unauthenticated remote attackers to read arbitrary server files, including account information, through specially crafted XML requests. It has a high FAUCET Risk Score of 99/100 and is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. While no public exploit code is available, the vulnerability has garnered significant community discussion and media coverage, indicating its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.09CPE matchmatch criteria | cpe:2.3:a:northgrid:proself:*:*:*:*:mail_sanitize:*:*:* | ||
< 1.66CPE matchmatch criteria | cpe:2.3:a:northgrid:proself:*:*:*:*:gateway:*:*:* | ||
< 5.63CPE matchmatch criteria | cpe:2.3:a:northgrid:proself:*:*:*:*:enterprise:*:*:* | ||
< 5.63CPE matchmatch criteria | cpe:2.3:a:northgrid:proself:*:*:*:*:standard:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.