CVE-2023-7307
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-27

Last updated on: 2025-08-29

Assigner: VulnCheck

Description
Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), or other impacts depending on parser behavior. The vulnerability is due to improper configuration of the XML parser, which allows resolution of external entities without restriction. This product is nowΒ integrated into their IAM (Internet Access Management) platform and an affected version range is undefined.Β Exploitation evidence was first observed by the Shadowserver Foundation on 2023-09-06 UTC.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-27
Last Modified
2025-08-29
Generated
2026-05-06
AI Q&A
2025-08-28
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
sangfor behavior_management_system *
sangfor iam 12.0.23
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an XML external entity (XXE) injection in the Sangfor Behavior Management System's /src/sangforindex endpoint. It allows a remote unauthenticated attacker to send specially crafted XML data containing external entity definitions. Due to improper XML parser configuration, the system processes these external entities without restriction, which can lead to disclosure of internal files, server-side request forgery (SSRF), or other impacts depending on how the XML parser behaves.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized disclosure of internal files, which may expose sensitive information. It can also enable server-side request forgery (SSRF), allowing attackers to make unauthorized requests from the server, potentially accessing internal systems or services. These impacts can compromise system confidentiality and integrity.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart