HACKR.GG
LabsVaultDB — NoSQL Login Bypass
NoSQL InjectionEasy

VaultDB — NoSQL Login Bypass

VaultDB's login API passes your JSON straight to a NoSQL-style comparison. Send a MongoDB \$ne operator as your password and bypass authentication entirely.

Step-by-step walkthrough
// Objective

Bypass the MongoDB-backed login by injecting a $ne operator in the password field.

ToolkitBrowserBurp Suitecurl
// Machine control
Checking session...
// Submit flag