XXE SVG Hostname

Returns an SVG payload with XXE to get files

/sh

attempts to get /etc/hostname

SVG with XXE payloads

Last modified March 19, 2025: more docs on filters (3e4f713)