Launch a browser from ZAP, enter XML in that form and submit it.
Then run the active scanner on the relevant request.
Note that ZAP may only try XML attacks if it recognises that the request is really XML. Submiting XML via a form is not usual, and so not something that ZAP will do unless its obviously XML. A standard HTML POST will not obviously be XML.
Launch a browser from ZAP, enter XML in that form and submit it. Then run the active scanner on the relevant request. Note that ZAP may only try XML attacks if it recognises that the request is really XML. Submiting XML via a form is not usual, and so not something that ZAP will do unless its obviously XML. A standard HTML POST will not obviously be XML.