VulnerableLightApp: a deliberately vulnerable .NET 10 REST and GraphQL API with about thirty CWE-mapped flaws, from SQL injection, XXE and insecure deserialization to JWT forgery, SSRF, command injection and a backdoor.
Not startedDockercommit 2554340x86_64 · aarch64Secret
Get a token from the API, then exploit as many of its vulnerabilities as you can.
The brief for this lab lives in its repository.