EastVale
easyFree

EastVale

EastVale is a youth soccer league site where team managers keep their team page up to date. Browse the teams, and if you run one, upload your club crest and print the roster.

xxesvgfile-uploadxml-external-entityfile-disclosure
phpapachenginx

The Scenario

EastVale runs recreational soccer across the valley. Team managers upload a club crest

and print a roster sheet for match day. A parent noticed their team's printed roster

came out with a line of text on the crest that nobody had typed into the site.

Look at EastVale the way a team manager would, starting from the crest upload, and work

out how something the site was never given could end up printed on the roster.

Lab Intel

Synopsis

EastVale accepts a team crest as SVG and draws it onto a generated roster PDF. The crest is parsed server-side with PHP DOMDocument using LIBXML_NOENT | LIBXML_DTDLOAD, so external entities are resolved. A crest carrying <!DOCTYPE svg [<!ENTITY x SYSTEM "file:///flag.txt">]> with &x; referenced in a <text> element reads /flag.txt into the text that is printed on the roster. First lab with SVG XXE as the primary (and only) vulnerability.

Architecture

An easy, one-hop XXE lab on two containers (nginx gateway + PHP 8.2/Apache). The only interesting surface is the per-team crest upload, which accepts an SVG and renders its <text> content onto a roster PDF (GET /roster.php?team=...). The upload looks like an image upload, hiding that SVG is XML. roster.php parses the stored SVG with DOMDocument($svg, LIBXML_NOENT | LIBXML_DTDLOAD) and prints each <text> node's content, so an external-entity crest reads /flag.txt straight into the PDF. The flag is only at /flag.txt (outside the webroot) and is reachable only through the entity.

Who It's For

Beginners meeting XXE for the first time, specifically the SVG-is-XML insight. The recon is realising the crest is parsed as XML; the payload is a single DOCTYPE SYSTEM entity referenced in a <text> element; the read is the roster PDF.

Skills You'll Practice

  • Recognising that an SVG upload is parsed as XML
  • Writing a DOCTYPE external entity that reads a local file
  • Referencing the entity in a rendered <text> element
  • Reading the leaked file out of a generated PDF

What You'll Gain

  • The SVG-is-XML / image-upload-is-XXE instinct
  • A reusable file:// external-entity read via an upload that gets parsed
  • Why rendering untrusted SVG server-side needs entity resolution disabled

Ready to hack EastVale?

This lab is free. Sign up and start hacking.

EastVale | WebVerse Pro Lab