Hunting for bugs in GraphQL APIs (Demo)
Lab: https://brokencrystals.com
https://brokencrystals.com/graphql is a vulnerable entry point where introspection is enabled. Attacker can chain this misconfiguration and chain it with sql injection.
GraphQL voyager: https://graphql-kit.com/graphql-voyager
#hackerone #bugbounty #graphql