Embedthis Appweb 7.0.1 protecting its site with digest authentication, vulnerable to CVE-2018-8715: an Authorization header with only username=admin skips the password check in authCondition, and the server answers with an authenticated session cookie.
Not startedDockercommit 6680c04x86_64 · aarch64Secret
Exploit CVE-2018-8715 to bypass Appweb's authentication as admin and read the protected page.
The brief for this lab lives in its repository.