#35351 [W&A-Insight] Password Length Bypass in Shardeum Authentication System
Description
I intercepted the request made during the login process and altered the payload to include a password that does not meet the 8-character minimum.
Despite sending a password shorter than the required length, the system allowed me to successfully authenticate.Proof of Concept
Proof of Concept
Previous#35598 [W&A-Insight] Access to debug endpoints without any protectionNext#35537 [W&A-Insight] json rpc server websocket remote crash
Last updated
Was this helpful?