20,000 USDC
View results
Submission Details
Severity: high

When borrower use refinance he can steal all of the funds in the contract

Summary

When borrower use refinance he can steal all of the funds in the contract

Vulnerability Details

In the refinance function there is no check for the debt value, setting very high debt will lead to else if which states that the loan.loanToken will transfer to msg.sender the debt - detbTopPay-fee

Impact

Stealing all of the funds

Tools Used

Manual Review

Recommendations

Check the debt that the borrower is setting

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.