← All Labs
🛡 INJECTION INTERMEDIATE +100 XP · +45 no-hint bonus

XXE — External Entity File Read

DocParse accepts XML uploads and parses them with external entities enabled. Inject an external entity reference that reads /etc/passwd from the server's filesystem.

https://bookshop.local/search