🟢Unprotected admin functionality

This lab has an unprotected admin panel.

Solve the lab by deleting the user carlos.

initial web page
URL changed

Clicking on "My account" on the top right changed the URL to website.net/login.

robots.txt showed something interesting

Accessing website.net/robots.txt showed a link that seems like the administrator's panel.

able to delete users

Accessing website.net/administrator-panel brought us to the admin control panel where normal users can delete existing users.

Last updated