Get the latest tech news
Hacking with PDF (2022)
Inspiration of how we can use PDF as an attack vector and perform multiple attacks with huge subsequences to the victim.
Acrobat has several types of built-in Popup Windows (alert, response, and file open), as well as functions for creating custom dialogs. In normal XSS you need to make sure the syntax is correct and valied, the same principle is applied to PDF except the injection is inside an object, such as javascript, text stream or annotation URI. The text entered in this box will be returned to the account variable if the user presses the OK button to exit the dialog.
Or read this on Hacker News