# Proself XXE Flaw Exploited in Japan

Published: 2023-10-25 · Severity: high
Canonical: https://vorant.io/reports/9533369c-a922-56c2-9076-0347e764423a/proself-xxe-flaw-exploited-in-japan

> An actively exploited XML external entity (XXE) vulnerability in Northgrid's Proself online storage software allows attackers to steal account credentials and files from servers.

Japan's IPA issued an alert regarding a vulnerability in Proself, an online storage package developed by Northgrid Corporation. The flaw stems from improper handling of XML External Entity (XXE) references, allowing an attacker to submit crafted XML requests that cause the server to disclose arbitrary files, including files containing account information.

IPA confirmed that exploitation of this vulnerability has already been observed in the wild, prompting an urgent call for administrators to apply vendor-supplied updates or implement workarounds immediately. All editions and versions of Proself are affected. For Proself Enterprise/Standard Edition Ver.4 and earlier, which have reached end-of-support and will not receive patches, the vendor recommends discontinuing use or migrating to Ver.5 or later.

The vulnerability was rated 7.5 (Important) under CVSS v3 and 5.0 under CVSS v2. Given the active exploitation and potential for credential and file theft from exposed enterprise storage servers, organizations using Proself should prioritize patching or applying interim mitigations provided by the vendor.

## Mentioned in this report

- Vulnerabilities: CVE-2023-45727 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/20231018-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9533369c-a922-56c2-9076-0347e764423a/proself-xxe-flaw-exploited-in-japan.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
