setPool and updateInterestRate functions in Lender.sol contract allow the lender to change the interest rate to up to 1000% at any time without a delay, this also includes frontrunning the borrowers' transactions.
The arbitrary change of interest rates may be unexpected for borrowers and can result in an inability to repay the loan on time.
Manual Review
Consider adding a delay (for instance: 1 day) for the interest rate update to go live in both the setPool and updateInterestRate functions.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.