JavaScript : XML external entity (XXE) injection