A Flask blog (login admin/admin) with an /admin page backed by GraphQL queries: one pings a server with nc through os.system, one looks a user up with a raw SQL filter.
Not startedDockercommit 82e7bb2x86_64 · aarch64Secret
Inject through the GraphQL arguments of the admin features to run an OS command and to dump data with SQL injection.
The brief for this lab lives in its repository.