Bypassed or command injection

Disclosed: 2015-01-01 03:41:26 By shivathegame To blockio
Unknown
Vulnerability Details
Respected sir, Step1:sign up an account Step2:set secret pin Step3:After that a tick box is asking " I will lose my coins if I forget my Secret PIN and Secret Mnemonic. I know this.".. Step4:If you check the tick box , the button "done" will enable.It is mandatory to check the box. The bug is, I bypassed this tick box feature.Without checking the tick box i applied command injection to the done button. I changed the disabled to enabled in the coding part of the done button.Then i clicked done button without accepting the tickbox. Please check the video for details..
Actions
View on HackerOne
Report Stats
  • Report ID: 34917
  • State: Closed
  • Substate: informative
  • Upvotes: 2
Share this report