PortSwigger Web Academy: Exploiting NoSQL Injection to Extract Data

Alex Rodriguez
4 min readSep 29, 2023

Hello, World! This blog post will serve as a walkthrough of PortSwigger’s Web Academy new NoSQL Injections lab #3, “Exploiting NoSQL injection to extract data.” Let’s go for it!

Glossary

NoSQL Database — refers to a database that does not implement table-based storage mechanisms but instead leverages an alternative…

--

--

Alex Rodriguez

I am an Offensive Security Engineer @ Amazon who writes about cybersecurity and anything related to technology. Opinions are my own.