fixed XML external entity (XXE) vulnerability