Rating:

TLDR: Blind SQL injection to iterate through admin password and recieve flag.

Original writeup (https://jaquiez.github.io/Blog/UMASSCTF2022/#Venting).