2 challenges available. Find the flag, submit it, earn points.
A login form is vulnerable to SQL injection. Login without credentials.
A comment section is vulnerable to stored XSS. Steal the admin cookie.