Login to any Boid account using Anchor and Telos account

Bug report template

Bug name

can use advance login to login to any BOID account


When searching for a BOID ID and loading the account you can use Anchor and Telos account to login to the account.

How to exploit

Search for a valid BOID ID, used advance login and login with Anchor account even if you are not the owner

Exploitation results

Once you are logged in with a Telos account you can try to update account information but it does not update (good) I have not tried to add an owner while logged in but assume it wouldn’t let you.

The goal with the UI is just to have basic usability for users to test the system while a new UI is being designed. Since the UI is considered a temporary prototype these kinds of bugs won’t be fixed. In any case, we appreciate your feedback!

