ZeroHour

CVE-2023-45727

KEVniche1

Unauthenticated XXE File-Read in North Grid Proself (CVE-2023-45727)

CISA: North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

CVSS 3.1
7.5 high
EPSS
4%p89
Published
()
KEV added
AI analysis

Proself, a self-hosted groupware/webmail product line from Japan's North Grid, improperly restricts XML external entity references (CWE-611) when processing XML data submitted to the server. A remote, unauthenticated attacker can send a specially crafted request containing malformed XML that triggers XXE resolution, allowing the attacker to read arbitrary files on the server, including files containing account information. Successful exploitation therefore primarily threatens confidentiality — exposed account credentials and sensitive data on the server — with no impact on integrity or availability per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N). Organizations running Proself Enterprise/Standard Edition 5.62 or earlier, Gateway Edition 1.65 or earlier, or Mail Sanitize Edition 1.08 or earlier are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-12-03, confirming exploitation in the wild, and EPSS estimates a 3.5% probability of exploitation in the next 30 days (89th percentile); no public PoC is known.

What to do: Upgrade all Proself editions to fixed releases per North Grid's guidance — beyond Ver5.62 for Enterprise/Standard, beyond Ver1.65 for Gateway, and beyond Ver1.08 for Mail Sanitize — or discontinue use of the product if mitigations are unavailable, per CISA's required action. Prioritize internet-facing Proself instances, review web/application logs for suspicious XML-containing requests, and rotate exposed account credentials since account information files are the primary target of this file-read flaw.

Affected
North Grid Proself Enterprise/Standard EditionVer5.62 and earlier
North Grid Proself Gateway EditionVer1.65 and earlier
North Grid Proself Mail Sanitize EditionVer1.08 and earlier
Estimated exposure
nichelikely on the order of hundreds of internet-exposed deployments worldwide (niche Japanese self-hosted product) — Proself is a niche self-hosted Japanese groupware/webmail/gateway line sold by North Grid with no public install counts in the available data; deployments are concentrated in Japanese organizations, so externally reachable instances are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

CISA Known Exploited Vulnerability
Affected
North Grid Proself
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
northgrid
Products
proself
Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news