Skip to content
Vulnerability field guide

XML External Entity

An XML parser that resolves external entities will fetch any file or URL an attacker names. Here is how XXE turns a document upload into local file disclosure and SSRF, and the parser settings that stop it cold.

4 articles 18 min total Overview to advanced techniques