webProeasy
Lab 298 — PayLedger — SQL Injection via GraphQL Date Filters
hackadvisor
Task: Payment analytics platform with GraphQL API, date filter parameters (fromDate/toDate) passed unsanitized to SQLite query. Solution: Used UNION-based SQL injection through GraphQL fromDate argument to enumerate sqlite_master schema and extract flag from admin_secrets table.
$ ls tags/ techniques/
union_based_sqligraphql_introspectionsqlite_schema_enumerationdate_parameter_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 290 — PayLedger — GraphQL Broken Access Control— hackadvisor
- [web][Pro]Lab 198 — PayrollSync — Broken Auth via GraphQL Introspection— hackadvisor
- [web][Pro]Lab 103 — DataPilot — AI SQL Injection via Natural Language Query— hackadvisor
- [web][Pro]Lab 31 — PayStream — IDOR in GraphQL Billing API— hackadvisor
- [web][Pro]Lab 267 — RestForge — SQL Injection in Dynamic Data Endpoint— hackadvisor