We covered a simple demonstration of XML External Entity Injection vulnerability which is part of OWASP Top 10. This was covered as part of HackTheBox baby WAFfles order challenge.
Video Walkthrough
Show Comments