News

We recently held a CTF event in which a team attempted to complete the challenge 'Exfiltrate the entire DB schema definition via SQL Injection' by exploiting SQL injection in the login API endpoint.
The XML schema definition language (XSD) validation has some limitations regarding SQL columns that use the xml data type. The following table provides details about those limitations and guidelines ...