🟢Unprotected admin functionality
This lab has an unprotected admin panel.
Solve the lab by deleting the user carlos.


Clicking on "My account" on the top right changed the URL to website.net/login.

Accessing website.net/robots.txt showed a link that seems like the administrator's panel.

Accessing website.net/administrator-panel brought us to the admin control panel where normal users can delete existing users.
Last updated