A Django 4.0.5 application on PostgreSQL, vulnerable to CVE-2022-34265: the kind argument of Trunc() and the lookup_name of Extract() are inserted into SQL without escaping, and the page passes the date parameter straight into Trunc.
Not startedDockercommit eccf886x86_64 · aarch64Secret
Exploit CVE-2022-34265 to inject SQL through Django's Trunc and read the flag from the database.
The brief for this lab lives in its repository.