PortSwigger Academy on GraphQL - Accidental exposure of private GraphQL fields

In this video, we walkthrough a lab from the PortSwigger Web Security Academy titled Accidental exposure of private GraphQL fields. It is marked as Practitioner difficulty. The objective is that the lab contains an access control vulnerability whereby you can induce the API to reveal user credential fields. To solve the lab, sign in as the administrator and delete the username carlos. We will use Burp Suite to solve the lab. Happy hacking! Website: https://owlhacku.com This content is for educational purposes only. Security testing should only be performed on systems you own or have explicit permission to test. Happy hacking!