Does the vulnerability permit access to a directory index, in order to identify the filenames of exciting attachments to transmit?
<script>
fetch(".").then(r => console.log(r));
fetch("/").then(r => console.log(r));
</script>
The console show errors when these URLs are loaded: TypeError: NetworkError when attempting to fetch resource. test.html:2:1