URL: https://lab03.sqrsec.com/

Difficulty: Medium

Notes:

  1. No password/account bruteforce is needed!

  2. XSS is out of scope

  3. Only the web interface port 443 is in-scope

Objective

  1. Dump the vault and extract the flag value. Format: UUID