VYPR
High severity7.5CISA KEVNVD Advisory· Published Oct 18, 2023· Updated Jun 17, 2026

CVE-2023-45727

CVE-2023-45727

Description

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Northgrid/Proself4 versions
    cpe:2.3:a:northgrid:proself:*:*:*:*:enterprise:*:*:*+ 3 more
    • cpe:2.3:a:northgrid:proself:*:*:*:*:enterprise:*:*:*range: <5.63
    • cpe:2.3:a:northgrid:proself:*:*:*:*:gateway:*:*:*range: <1.66
    • cpe:2.3:a:northgrid:proself:*:*:*:*:mail_sanitize:*:*:*range: <1.09
    • cpe:2.3:a:northgrid:proself:*:*:*:*:standard:*:*:*range: <5.63
  • Range: <=Ver1.65
  • Range: <=Ver1.08
  • Range: <=Ver5.62
  • North Grid Corporation/Proself Enterprise/Standard Editionv5
    Range: Ver5.62 and earlier
  • North Grid Corporation/Proself Gateway Editionv5
    Range: Ver1.65 and earlier
  • North Grid Corporation/Proself Mail Sanitize Editionv5
    Range: Ver1.08 and earlier

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.