webProeasy

Lab 298 — PayLedger — SQL Injection via GraphQL Date Filters

hackadvisor

Task: Payment analytics platform with GraphQL API, date filter parameters (fromDate/toDate) passed unsanitized to SQLite query. Solution: Used UNION-based SQL injection through GraphQL fromDate argument to enumerate sqlite_master schema and extract flag from admin_secrets table.

$ ls tags/ techniques/
union_based_sqligraphql_introspectionsqlite_schema_enumerationdate_parameter_injection

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups