Rating:
TLDR: XSS to exfilitrate admin cookie, bypass CSS with eval sink on included JS file.
I don't remember