← All Labs
🛡 INJECTION INTERMEDIATE +80 XP · +35 no-hint bonus

XPath Injection — Login Bypass

XmlAuth stores users in an XML doc and authenticates by building XPath queries from form input. Inject XPath syntax to bypass authentication and log in as admin.

https://bookshop.local/search