Skip to main content

Unprotected admin functionality

1

We can go to the /robots.txt file to check is any pages are disallowed for web crawler.

2

As we can see, the /administrator-panel page is blocked.

Let's visit it through the browser.

3

We can now delete the carlos user.

4

We have solved the lab.

5