### [CVE-2016-3720](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3720) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors. ### POC #### Reference No PoCs from references. #### Github - https://github.com/0ang3el/Unsafe-JAX-RS-Burp - https://github.com/ARPSyndicate/cvemon - https://github.com/Anonymous-Phunter/PHunter - https://github.com/CGCL-codes/PHunter - https://github.com/argon-gh-demo/clojure-sample - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/gitrobtest/Java-Security - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/rm-hull/nvd-clojure - https://github.com/scrumfox/Secapp