
Exploiting XXE Vulnerabilities on Microsoft SharePoint Server and Cloud via Confused URL Parsing
The impact of the vulnerability is limited at present, but thanks to https://x.com/chudyPB for providing a clever bypass idea.
change these:

pip install requests requests_ntlm flask
python CVE-2024-30043-XXE.py
test on Microsoft Sharepoint Server 2019(16.0.10409.20027):
