A tester discovers a web application that generates PDF files by passing user input to a headless browser. The tester injects an iframe pointing to an internal IP. What vulnerability is this?
-
A
XSS via PDF
-
B
Server-Side Request Forgery (SSRF)
-
C
HTML injection
-
D
Open redirect