A deliberately vulnerable Java web application built on Struts 2, Spring, Hibernate and MySQL, with one section per OWASP Top 10 (2013) risk: injection, broken authentication, XSS, IDOR, misconfiguration, sensitive data exposure, missing access control, CSRF, vulnerable components and open redirects.
Not startedDockercommit ecddeedx86_64 · aarch64Secret
Exploit each OWASP Top 10 risk the application implements, from SQL and command injection to the vulnerable Struts component.
The brief for this lab lives in its repository.