A deliberately vulnerable banking application with a web front end, REST and GraphQL APIs and an AI support chat: SQL injection, broken authentication and JWT flaws, IDOR and BOLA, race conditions on transfers, SSRF, file upload and prompt injection.
Not startedDockercommit fbdfa0ax86_64 · aarch64Secret
Take over other customers' accounts and money, and reach the admin panel.
The brief for this lab lives in its repository.