XML External Entities (XXE)
<!-- Vulnerable code -->
<!DOCTYPE data [
<!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<user>
<name>&xxe;</name>
</user>
<!-- Secure code (disable external entity resolution) -->
<!DOCTYPE data [
<!ENTITY % xxe SYSTEM "file:///etc/passwd">
%xxe;
]>
<user>
<name>John Doe</name>
</user>
Last updated