web warmup

My admin panel

Points: 51
Solves: 151

I think I've found something interesting, but I'm not really a PHP expert. Do you think it's exploitable?

The flag format is: p4{letters_digits_and_special_characters}.
