Rapid7's Hackazon: a vulnerable online store with an AJAX interface, strict checkout workflows and a RESTful API used by its companion mobile app, full of SQL injection, XSS, command injection and access control flaws.
Not startedDockercommit d326b13x86_64 · aarch64Secret
Find and exploit the vulnerabilities of the Hackazon store, its back office and its REST API.
The brief for this lab lives in its repository.