My initial attempt to exploit XXE by fetching local files failed. Since I had no knowledge of other backend systems, I decided to try out-of-band interaction by reaching my Burp Collaborator. I crafted a simple payload using my Burp Collaborator URL:
After sending this request and polling Burp Collaborator, I observed multiple DNS lookup requests. This successful interaction confirmed the exploit, and the lab was solved.