A template engine that fetches user-supplied URLs is an RFI finding
Attacker-controlled remote includes escalate to code execution, not just a bad fetch.
#CPTS #PenTesting #WebSecurity #AppSec
Full CPTS explanation, free: https://navyduck.com/cpts/web-application-penetration-testing/q203
