CVE-2023-7307: Sangfor Behavior Management System XML External Entity Injection

Published Aug 27, 2025
·
Updated

Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), or other impacts depending on parser behavior. The vulnerability is due to improper configuration of the XML parser, which allows resolution of external entities without restriction. This product is now integrated into their IAM (Internet Access Management) platform and an affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-09-06 UTC.

Affected Software

1 affected component
Sangfor Behavior Management System

Event History

Aug 27, 2025
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-7307?

CVE-2023-7307 is considered a high-severity vulnerability due to its potential for remote unauthenticated exploitation.

2

How can I mitigate CVE-2023-7307?

To mitigate CVE-2023-7307, ensure that XML processing is disabled or tightly restricted, and validate XML input thoroughly.

3

What is the impact of CVE-2023-7307?

CVE-2023-7307 allows remote attackers to perform XML external entity injection, potentially leading to data exposure or server-side request forgery.

4

Which version of Sangfor Behavior Management System is affected by CVE-2023-7307?

All versions of the Sangfor Behavior Management System that contain the /src/sangforindex endpoint are affected by CVE-2023-7307.

5

Is CVE-2023-7307 easy to exploit?

Yes, CVE-2023-7307 can be easily exploited by a remote unauthenticated attacker through crafted XML data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203