This is a small flask web-app to demo a class of XML vulnerabilities at ISIG Auckland, October 2016 and OWASP Day New Zealand 2017.
This project is littered with intentional security vulnerabilties. If you implement any of this project in a production environment, Bad Things (TM) will happen.