SQLMAP injects data in json format
When the injection point is in the json format data, the SQLMAP may be stupid and can't find the injection point.
Using-p to specify parameters is not good for specifying fields in json format.
At this point, you need to manually modify the injected json data so that SQLMAP can find the injection parameters:
The json input that causes SQLMAP to be stupid looks like this:
{"name": ["string"]}
Changing it to either of the following forms allows SQLMAP to find the injection point (rather than skip it directly):
/ / method 1, add * {"name": ["string*"]} / / this is seen from foreign forums / / method 2, delete the brackets {"name": "string"}