Unprotected admin functionality¶
Description¶
This lab has an unprotected admin panel.
Reproduction and proof of concept¶
Go to the lab and view
robots.txtby appending/robots.txtto the lab URL. Notice that theDisallowline discloses the path to the admin panel.In the URL bar, replace
/robots.txtwith/administrator-panelto load the admin panel.Delete
carlos.
Exploitability¶
An attacker will need to delete the user carlos.