# Proself online storage software contains a critical XXE vulnerability (CVE-2023-45727)…

Published: 2023-10-25 · Severity: critical
Canonical: https://vorant.io/reports/b7acf082-429c-42c3-be44-d667febfa0f5/proself-online-storage-software-contains-a-critical-xxe-vulnerability-cve-2023

> Proself online storage software contains a critical XXE vulnerability (CVE-2023-45727) actively exploited to steal server files including credentials; immediate patching required.

Japan's IPA has issued an alert for a critical XML External Entity (XXE) vulnerability affecting Proself, an online storage package developed by North Grid Corporation. The vulnerability allows attackers to process malicious XML data through crafted requests, enabling theft of arbitrary files from the server including account credentials. Active exploitation of this vulnerability has been confirmed in the wild, prompting urgent remediation recommendations.

All editions and versions of Proself are affected by this vulnerability. The vendor has released patches and recommends immediate updates to the latest version. For organizations unable to immediately patch, temporary workarounds are available. Users of legacy versions (Enterprise/Standard Edition Ver.4 and earlier) should discontinue use or migrate to Ver.5 or later as these versions are end-of-life and will not receive security updates.

The vulnerability carries a CVSS v3 base score of 7.5 (High severity) and has been actively exploited, making it a priority remediation target for organizations running Proself in their environments.

## Mentioned in this report

- Vulnerabilities: CVE-2023-45727 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2023/20231018-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b7acf082-429c-42c3-be44-d667febfa0f5/proself-online-storage-software-contains-a-critical-xxe-vulnerability-cve-2023.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
