A public-facing permits API is abused with SQL-injection-style input. What is the attack vector?
Select an answer to reveal the explanation.
Short Explanation
The attacker did not need the VPN or a vendor laptop—they typed hostile input into the permits API. That is a vulnerable public web application. Keep the vector on the app that accepted the injection.
Full Explanation
SQL-injection-style abuse of a public permits API is an attack against a vulnerable civic web application. The city's VPN, an unmanaged vendor laptop, and an exposed camera RDP listener are separate vectors that this input-abuse evidence does not establish. Classify from the exploited interface.