Product: Proself WebDAV Server
Date: 2024-12-04 10:08:59
Information: Trending, Fix Available, Active Exploitation
The United States Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a critical XML External Entity (XXE) vulnerability in Proself Enterprise/Standard, Gateway, and Mail Sanitize Editions. This vulnerability allows unauthenticated attackers to access sensitive account information on affected servers.
Technical Summary
The vulnerability allows an unauthenticated remote attacker to perform XML External Entity (XXE) attacks by sending specially crafted XML data to Proself services. This can lead to the exposure of arbitrary files on the server, including sensitive account information, resulting in data breaches and potential further compromise of the affected systems.
Affected versions:
- Enterprise/Standard Edition: Ver5.62 and earlier
- Gateway Edition: Ver1.65 and earlier
- Mail Sanitize Edition: Ver1.08 and earlier
Recommendations
To fully mitigate the vulnerability:
1 – Update to the patched versions:
- Enterprise/Standard Edition: update to Ver5.63 or later
- Gateway Edition: update to Ver1.66 or later
- Mail Sanitize Edition: update to Ver1.09 or later
2 – Discontinue the use of unsupported versions:
- If you are using Enterprise Edition/Standard Edition Ver4 or earlier, discontinue use immediately or update to supported versions to prevent potential exploitation and data leaks.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
