Proself XXE Flaw Exploited in Wild
An actively exploited XML external entity vulnerability in Northgrid's Proself file-sharing software lets attackers steal account credentials and arbitrary files.
IPA (Information-technology Promotion Agency, Japan) issued an advisory for an XML External Entity (XXE) vulnerability in Proself, an online storage/file-sharing package developed by Northgrid Corporation. By sending specially crafted XML data to the product, an attacker can force the server to disclose arbitrary files, including stored account credentials, without authentication.
The advisory states that exploitation of this vulnerability has already been observed in the wild, prompting IPA to urge immediate patching or workaround deployment. All editions and versions of Proself are affected. The vendor has released updates for supported versions; for Proself Enterprise/Standard Edition Ver.4 and earlier, which have reached end of support, no patch will be issued and users are advised to migrate to Ver.5 or later, or discontinue use. A subsequent update on October 26, 2023 added details on interim mitigations that can be applied until the update is installed.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/20231018-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free