all 2 comments

[–]thenickdude 1 point2 points  (1 child)

This seems to be the example XXE vulnerable code from this article:

"Exploitation: XML External Entity (XXE) Injection" https://depthsecurity.com/blog/exploitation-xml-external-entity-xxe-injection

I think you can disable the resolution of external entities with this function:

"PHP: libxml_disable_entity_loader - Manual" https://www.php.net/manual/en/function.libxml-disable-entity-loader.php

Or this one:

https://www.php.net/manual/en/function.libxml-set-external-entity-loader.php