Published onJuly 6, 2025FlagYard - Web - OhMyQLSQL-InjectionJWTWEBExploitationGraphQLExploiting a GraphQL vulnerability through SQL injection to bypass authentication and gain unauthorized access. By manipulating the JWT token, we set flagOwner to true and retrieve the flag.