setPool
function in Lender.sol
contract does not check if pool parameters p.loanToken
and p.collateralToken
are contracts.
Manual Review
Use OpenZeppelin isContract(address account) function to check if the input address is a contract
Example:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.