Forum Discussion
immervivesolver
5 months agoBronze III
Trick or Treat: Manor of Madness
Any hints or close payloads for last task
- 5 months ago
This should nudge you in the right direction - MongoDB $where operator JavaScript injection - Web Application Vulnerabilities | Invicti
Samh051
5 months agoBronze III
Sure, the query i used is
$where":"this.name == '' && this.incantation == '';1==1"The aim was to discover you could use JavaScript injection to evaluate the query to true.