web-intro
*  
web  
cyberedu

Are you an admin
The page returned access denied. This made me check the cookies


The session cookie is a JWT token.

I used flask-unsign to get the password and create a new cookie with permissions set to true.
https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/flask





After using the new cookie i got the flag.


CTF{66bf8ba5c3ee2bd230f5cc2de57c1f09f471de8833eae3ff7566da21eb141eb7}