How it defends against injection and XSS attempts
This web application is secured by SQLGuardJS, a request verification layer that intercepts SQL injection and XSS payloads. Your objective is to discover a bypass technique that circumvents the guard's detection mechanisms and successfully executes a malicious SQL query against the backend SQLite database.
A secret flag is hidden within the flags table in the database. You can try to bypass the Authentication endpoint or extract data via the Search endpoint.
If you successfully bypass the filter, your output will look something like this: