How to run an XXE injection via an SVG Image Upload!

Опубликовано: 30 Апрель 2026
на канале: Intigriti
15,753
270

👩‍🎓👨‍🎓 Learn how you can run a successful XXE injection via an image upload functionality. We are going to achieve this by uploading an SVG (scalable vector graphics) file.

Overview:
00:00 Intro
00:21 Lab overview
01:22 What are SVG files?
02:24 How does the HTTP request look like?
03:06 Learning about payloads
03:51 Exploiting the app
05:36 Conclusion

For more information, check out https://blog.intigriti.com/hackademy/....

🔗 Portswigger XXE Challenge: https://portswigger.net/web-security/...
🔗 XXE Payloads on Github: https://github.com/swisskyrepo/Payloa...
---

🧑‍💻 Sign up and start hacking right now - https://go.intigriti.com/register

👾 Join our Discord - https://go.intigriti.com/discord

🎙️ This show is hosted by   / pascalsec   (‪@Hacksplained‬ ) &   / intigriti  

👕 Do you want some Intigriti Swag? Check out https://swag.intigriti.com/