A attack using SSRF to obtain CSRF Process Some subdomain b.site.com allows SSRF Some subdomain a.site.com allows CORS to enable localhost, protected against CSRF Launch SSRF against b.site.com from a.site.com