Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Playing with Content-Type – XXE on JSON Endpoints

Summary

By switching a JSON request's Content-Type to application/xml, testers can sometimes reach an unanticipated XML parser on the server and trigger XXE, enabling file reads, UNC access, or SSRF.
Published
Collected

original ↗