An application allows users to upload XML files that are parsed server-side. Which threat should be the HIGHEST priority in the threat model?
-
A
Cross-Site Scripting (XSS)
-
B
XML External Entity (XXE) injection
-
C
SQL injection
-
D
Cross-Site Request Forgery (CSRF)