The subject tells us to steal the administrator cookie. Stealing administrator cookie is usually linked with XSS.
On the web page, we have a form, and a contact tab. Let's try to enter some javascript on the form to see if there is a XSS vulnerability.
The URL : http://challenges2.france-cybersecurity-challenge.fr:5001/index.php?search=%3Cscript%3Ealert%28%22nul%22%29%3C%2Fscript%3E
Therefore, if we modify the value of the search parameter by some JavaScript to redirect the administrator to a webpage that we control, we might retrieve the administrator cookie if the administrator clicks on the link that we will send through the contact form.