This lab contains an unprotected admin panel.
Solve the lab by deleting the user carlos.
I suspected there was an exposed admin functionality, so I tested multiple common login credentials:
admin : admin โadministrator : admin โI also attempted to brute-force potential admin panel paths:
/admin โ โ/administrator โ โ/admin-panel โ โ/administrator-panel โ โ
I successfully discovered the unprotected admin panel at:
<http://Domain-lab/administrator-panel>