Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-30043-XXE — Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing | Kitploit
Tools/GitHubGitHub/w01fh4cker/cve-2024-30043-xxe
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubw01fh4cker/cve-2024-30043-xxe

CVE-2024-30043-XXE

Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing

View Repository
332502 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-30043-XXE

Credit

The impact of the vulnerability is limited at present, but thanks to https://x.com/chudyPB for providing a clever bypass idea.

https://x.com/chudyPB

https://www.zerodayinitiative.com/blog/2024/5/29/cve-2024-30043-abusing-url-parsing-confusion-to-exploit-xxe-on-sharepoint-server-and-cloud

https://x.com/chudyPB/status/1797707100421751007

Usage

change these:

root@kitploit:~
pip install requests requests_ntlm flask
python CVE-2024-30043-XXE.py

test on Microsoft Sharepoint Server 2019(16.0.10409.20027):

Download Tool