Origin app, intentionally vulnerable. Served on pod payments-api-6c5466b765-wfk6f.
The same origin sits behind two hostnames so you can see a WAF's effect: open (no WAF) vs secure (wslproxy WAF, block mode).
/search?q=laptop/products?cat=deposit/statement?file=welcome.txt/ping?host=127.0.0.1/render?tpl=Hello/lookup?user=guest/bind?class.module.classLoader=x/fetch?url=https://acme.example/logo.pngPOST /api/login {"user":"admin","pass":{"$ne":null}}GET /api/accounts/9999POST /api/profile {"role":"admin"}GET /api/me with a forged bearer tokenPOST /api/import (XML)POST /graphqlPOST /api/merge {"__proto__":{"admin":true}}/api/redirect?to=https://evil.example