// HackTricks · Web Pentesting

PDF Upload: XXE and Same-Origin Policy Bypass

PDF Upload: XXE and Same-Origin Policy Bypass

PDF files can contain actions, forms, and references to external resources, so an upload feature may expose more than document-rendering risk. The linked research documents historical Adobe Reader issues involving external entities and a same-origin-policy bypass, often described as a CORS bypass. Treat its proof of concept as version-specific: reproduce it only with the affected reader and browser integration, and verify current behavior independently.[1]

References