[CTF] Lambda SQLi PrivEsc to Access Secret in Secrets Manager

Exploit a Lambda function’s SQL injection vulnerability to grant yourself privileges that let you access a secret from Secrets Manager you shouldn’t have access to. You’ve captured the flag when you’re able to read, in plaintext, the vault-password value. Inspired by CloudGoat’s Vulnerable Lambda scenario but slightly modified to challenge your understanding.

