Portable Data exFiltration: XSS for PDFs
Summary
Gareth Heyes shows how a single injected hyperlink can compromise PDFs: injecting PDF code to execute JavaScript, exfiltrate contents in Acrobat and PDFium, and trigger SSRF on server-side renders.
- Published
- Collected
Skip to content