🏢 AcmeCorp

PRACIVO LAB — INTENTIONALLY VULNERABLE
⚠️ Pracivo Security Lab — SSRF in webhook, XXE in XML upload, Open Redirect in login, CORS on API.

XML Document Upload

Submit an XML contact form. The server parses it and returns the data.

The default payload above tries XXE to read /etc/passwd — submit it and see what happens.