vulns.co
/
GKData.io MCP

Back to Playbooks

XXE Injection

Abuse XML external entity parsing to read files, perform SSRF, or exfiltrate data out-of-band.

Tags: xxe, xml, ssrf, file-read

Level: intermediate

Method

  1. Find XML sinks

    SOAP endpoints, file uploads (DOCX/SVG/XML), and APIs accepting application/xml. Also try switching a JSON endpoint's Content-Type to XML.

    Tools: Burp Suite

  2. Classic file read

    Declare an external entity pointing at a local file and reflect it in the response.

    <!DOCTYPE r [<!ENTITY x SYSTEM 'file:///etc/passwd'>]><r>&x;</r>
  3. Blind / OOB

    When there's no reflection, use an external DTD on your server to exfiltrate file contents over HTTP/DNS.

    interactsh-client -v

    Tools: interactsh

  4. SSRF via XXE

    Point the entity at internal services or cloud metadata to pivot.

Field notes

  • SVG and Office documents are XML - upload fields are a classic XXE vector.
  • Parameter entities (%) are needed for most blind/OOB exfiltration.

References