XXE
Brief
Impacts
OWASP TOP 10 : SSRF, DoS, RCE, XSS
The CVSS score of a XXE is 7.5 and its severity is Medium with :
CWE-611: Improper Restriction of XML External Entity.
CVE-2019-12153: Local File SSRF
CVE-2019-12154: Remote File SSRF
CVE-2018-1000838: Billion Laugh Attack
CVE-2019-0340: XXE via File Upload
XXE to SSRF
Payloads
Local File Inclusion
With bWAPP
XXE Billion Laugh Attack-DOS
XXE File Upload
XXE can be performed using the file upload method.
XXE to RCE
POC with XXELAB
Last updated
Was this helpful?