webPromedium

Lab 83 — DealStream — UNION SQL Injection in Public Search API

hackadvisor

Task: CRM platform with public search API where the scope parameter is directly interpolated into a SQLite WHERE clause. Flag is XOR-encrypted in admin_settings, decrypted only in admin panel. Solution: UNION-based SQLi to enumerate schema and extract admin reset token, then account takeover via password reset to access admin panel and view decrypted flag.

$ ls tags/ techniques/
union_based_sqlisqlite_schema_enumerationapi_parameter_injectionpassword_reset_token_extractionaccount_takeover

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups