When calling buyLoan()
function of Lender.sol
to buy a loan after an auction is started, there is no check for maxLoanRatio.
User may buy loan whose loan to collateral ratio is less than what they specified in their pools maxLoanRatio.
Pool lender may not get specified collateral for the loan, which also creates an issue in giving the loans to another pool.
Manual Review
Calculate the current loan ratio of the loan being auctioned and check it with the max loan ratio of the pool before completing the buyLoan
function transaction.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.