← All Labs
🛡 SQLI BEGINNER +70 XP · +30 no-hint bonus

SQL Injection — Login Bypass

MiniMail's login page builds its SQL query by string-concatenating your username and password. Log in as the admin without knowing the password.

https://bookshop.local/search