An intentionally vulnerable restaurant API built with FastAPI and PostgreSQL. Starting as a low-privileged API user, chain API flaws such as broken authorization, weak JWT handling and injection to reach root on the server.
Pas commencéDockercommit 0a63abbx86_64 · aarch64Secret
Escalate from a low-privileged API user to root on the server.
Le brief de ce lab se trouve dans son dépôt.