I am trying to get a better understanding of XML and XML injections along with LDAP, I can not seem to find the videos in security plus can someone help break this down for me?
XXE attacks and mitigations are covered in our OWASP Top 10 2017 series which you can find here...
I don't think we have anything specifically covering LDAP injections, but basically if an application is using LDAP to do things like authentication or information lookup/retrieval, you may be able to manipulate the query much like you do with a SQL injection.
OWASP covers this in more detail here...
I hope this helps you out.