Oh dear.
I've discovered another exploit in the profile photo thing.
If the user clicks submit with an empty field and no current pic. Then their points will increase anyway. You can do this 'til the cows come home.
This will also happen with an invalid file type.
It's doing the maths wrong too. I set it to pay 150 to add and to cost 500 to delete.
Payed out fine but deleting it took away 650. I uploaded another pic an did it again, this time it only took away 150. Did it again and it took away 300.
|