
A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys
This is a poc script to explot the xmlsec vulnerability CVE-2021-21239
To use this script you can either build the docker image or you can provide an rsa key yourself and run it assuming you have xmlsec installed
Vulnerability info: https://www.aleksey.com/pipermail/xmlsec/2013/009717.html