testPwned function in which user terminal data can be compromised by running the test. In this test the arbitrary command can be executed by the testPwned function.
this function in the test creates a malicious new file(youve-been-pwned) in the root directory of the project.
This function can be used to execute arbitrary commands on the user's terminal which can be used to compromise the user's data. So, there is no reason to have this function in the test.
creating a malicious file in the root directory of the project.
user's terminal data can be compromised by running the test.
Manual Review
Remove the testPwned function from the test.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.