Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-45727

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.206
EPSS Ranking 95.3%
CVSS Severity
CVSS v3 Score 7.5
Proposed Action
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.
Ransomware Campaign
Unknown
Products affected by CVE-2023-45727


Contact Us

Shodan ® - All rights reserved