We are greeted with this web-page
Then we log in with the credentials given to us:
test : Test123!
We get this:
We notice that there is a JWT token added onto our session:
We visit this website:
We set algorithm to none:
And we change the role to 'admin':
We get this final new token:
We set this value as of our token
We get this page:
Hence we get our flag.