A deliberately vulnerable REST API written in C# with ASP.NET Core and Entity Framework Core: SSO cookie authentication bypass, insecure JWT usage, weak password reset, SSRF, privilege escalation, insecure deserialization, XXE and SQL injection.
Not startedDockercommit d9bc201x86_64 · aarch64Secret
Exploit the API flaws to escalate from a registered user to an administrator.
The brief for this lab lives in its repository.