
Sfruttare le vulnerabilità XXE su Microsoft SharePoint Server e Cloud tramite Confused URL Parsing
L'impatto della vulnerabilità è al momento limitato, ma grazie a https://x.com/chudyPB per aver fornito un'idea intelligente di bypass.
modificare queste:

pip install requests requests_ntlm flask
python CVE-2024-30043-XXE.py
test su Microsoft Sharepoint Server 2019(16.0.10409.20027):
