A penetration tester is exploiting a web application and discovers an XML External Entity (XXE) vulnerability. Which TWO attacks can be performed using XXE?
Server-Side Request Forgery (SSRF) is a direct impact of XXE because an attacker can define an external entity that points to an internal URL, forcing the server's XML parser to fetch that URL on the attacker's behalf. This lets the attacker scan internal network segments, access cloud instance metadata (e.g., IAM credentials), or interact with internal services that are not exposed externally. The server's outbound request is the core of the XXE attack, making SSRF a primary and correct classification.
Why this answer
XXE can be used to read local files via external entities and also to perform SSRF by making the server request internal resources.