Damn Vulnerable Web Services: a Node.js application with REST, SOAP, XML-RPC and GraphQL interfaces backed by MongoDB and MySQL, covering more than 30 API and web service flaws such as XXE, NoSQL and SQL injection, JWT weaknesses, SSRF and insecure deserialization.
Not startedDockercommit ff51c46x86_64 · aarch64Secret
Exploit the API and web service vulnerabilities listed in the lab guide.
The brief for this lab lives in its repository.