20,000 USDC
View results
Submission Details
Severity: high

Missing checks for if pool interest rate is higher than the loan interest rate when refinance

Summary

Missing checks for if pool interest rate is higher than the loan interest rate when refinance.

Vulnerability Details

refinance(Refinance[] calldata refinances) can be called by a borrower to refinance a loan.

Borrower specifies the pool to refinance to and the loan will be updated, including loan.interestRate.

However, there is no checks for if pool interest rate is higher than the loan, borrower's loan might be refinaced to a pool with higher interest rate, results in the loan gets higher interest rate than before.

Impact

Borrower's loan gets refinanced to a higher interest rate.

Tools Used

Manual Review

Recommendations

Add checks for if pool interest rate is higher than the loan interest rate when refinance.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!