20,000 USDC
View results
Submission Details
Severity: medium

lack of interest rate check

Summary

When the loan is given to another pool in buyLoan function, there is no check to ensure that the interest rate of the new pool is higher than the previous pool.

Vulnerability Details

Scenario: Alice gets a loan with an interest rate of for example 10% , then Bob (the lender of the current pool) starts the auction for Alice's loan, now another lender can call the BuyLoan function to buys Alice's loan for a higher interest , lender can have two pools and use this method to increase interest rate .

Impact

It leads to the borrower paying more interest rate than expected or lender increases the interest rate .

Tools Used

Manual Review

Recommendations

Check buyer pool has not higher interest rate than seller pool .

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.