A deliberately vulnerable photo-sharing web application and API built on Node.js, Express and MongoDB, with flaws across the OWASP API Security Top 10: excessive data exposure, broken object level authorization, mass assignment, weak JWT handling, NoSQL injection and XSS.
Pas commencéDockercommit 0235e37x86_64 · aarch64Secret
Abuse the Pixi web application and API to read other users' data and reach the admin functions.
Le brief de ce lab se trouve dans son dépôt.