boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2023-45727

North Grid Proself
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0354   88.9   YES
AFFECTED
  Product                              Versions               Fixed
  Proself Enterprise/Standard Edition  Ver5.62 and earlier –  —
  Proself Gateway Edition              Ver1.65 and earlier –  —
  Proself Mail Sanitize Edition        Ver1.08 and earlier –  —
TIMELINE
  Oct 11  Reserved by jpcert
  Oct 18  Published (CNA: jpcert)
  Dec 3   Added to CISA KEV, remediation due 2024-12-24
CWE-611 · CNA: jpcert · CVSS v3.1 · 3 references · KEV due December 24, 2024

Description

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
October 11, 2023ReservedReserved by jpcert
October 18, 2023PublishedPublished (CNA: jpcert)
December 3, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-12-24

Affected

Affected products and packages — 3 rows
VendorProduct / PackageEcosystemVersion introducedFixed
North Grid CorporationProself Enterprise/Standard Edition—Ver5.62 and earlier—
North Grid CorporationProself Gateway Edition—Ver1.65 and earlier—
North Grid CorporationProself Mail Sanitize Edition—Ver1.08 and earlier—

Weaknesses

CWE-611

References (3)

Related

Authoritative record: CVE-2023-45727 at cve.org

Vendors: north grid

Weaknesses: CWE-611

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-45727 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.