PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.
Exploiting XXE to Perform SSRF


PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.

PortSwigger Web Security Academy: XXE in a stock-check XML endpoint, defining an external entity to read /etc/passwd off the server.