Skip to content

Create rsql-injection.md#1017

Merged
carlospolop merged 1 commit intoHackTricks-wiki:masterfrom
m3n0sd0n4ld:m3n0sd0n4ld-rsql_injection
Apr 14, 2025
Merged

Create rsql-injection.md#1017
carlospolop merged 1 commit intoHackTricks-wiki:masterfrom
m3n0sd0n4ld:m3n0sd0n4ld-rsql_injection

Conversation

@m3n0sd0n4ld
Copy link
Copy Markdown
Contributor

RSQL Injection is a vulnerability in web applications that use RSQL as a query language in RESTful APIs. Similar to SQL Injection and LDAP Injection, this vulnerability occurs when RSQL filters are not properly sanitized, allowing an attacker to inject malicious queries to access, modify or delete data without authorization.

@carlospolop
Copy link
Copy Markdown
Collaborator

Great, thanks for the PR @m3n0sd0n4ld

@carlospolop carlospolop merged commit 4f7d6db into HackTricks-wiki:master Apr 14, 2025
@m3n0sd0n4ld
Copy link
Copy Markdown
Contributor Author

Hi Carlos!

Thanks for letting me collaborate with your work, it is an honor and a pleasure!

Sorry for the delay in answering, but is it normal that it does not appear on the web?

I attach a screenshot of the search engine
hacktricks-rsql

Thanks in advance!

@m3n0sd0n4ld m3n0sd0n4ld deleted the m3n0sd0n4ld-rsql_injection branch April 21, 2025 08:41
@carlospolop
Copy link
Copy Markdown
Collaborator

The page also needed to be added into SUMMARY.md, I have added it, it should be public in some time!

@m3n0sd0n4ld
Copy link
Copy Markdown
Contributor Author

Sorry for the problem and thank you very much!

s3llh0lder pushed a commit to s3llh0lder/hacktricks that referenced this pull request Aug 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants