#ZDI #exploitation
This video demonstrates an XML eXternal Entity (XXE) injection vulnerability in the SharePoint Server discovered by ZDI researcher Piotr Bazydło. It affects both on-prem and cloud versions of SharePoint and can be triggered by a low-privileged user. The bug can be used for information disclosure or for NTLM relaying.
For full details on the vulnerability, read the blog at:
https://www.zerodayinitiative.com/blo...