We use Burp Suite to intercept the GET request, change the isAdmin cookie to True and we’ll get our flag: