SSRF

Server-side request forgery: making the server fetch a URL of the attacker's choosing, often to reach internal services.