Unprotected admin functionality
Description
This lab has an unprotected admin panel.
Reproduction and proof of concept
Go to the lab and view
robots.txt
by appending/robots.txt
to the lab URL. Notice that theDisallow
line discloses the path to the admin panel.In the URL bar, replace
/robots.txt
with/administrator-panel
to load the admin panel.Delete
carlos
.
Exploitability
An attacker will need to delete the user carlos
.