chainx-org / chainx-wallet-bug-bounty

The bug bounty program repository for ChainX wallet, signer and extension. Please submit issues and get reward.
3 stars 0 forks source link

"Export keystore" still works fine if inputting wrong wrong password #31

Open wanbihou opened 3 years ago

wanbihou commented 3 years ago

"Export keystore" still works fine if inputting wrong wrong password

Steps to recreate it:

  1. Install the windows wallet from the following link: windows:https://github.com/wliyongfeng/chainx2-signer/releases/download/1.1.0/ChainX-Signer-Setup-1.1.0.exe
  2. Create the wallet, and then select "Export keystore" from the dropdown menu 3.Input a wrong password on the "Input password" page
  3. Click the "Confirm" button Now the key can still be exported even the password is wrong.

Tested address is: 5HoKzSqGSrRSWxti2RwzFb4nbpGvJsxJdDXFcB2K5rqNG9y9