20,000 USDC
View results
Submission Details
Severity: high

missing access-control

Vulnerability Details

doesn't actually check if msg.sender does indeed owns the specified pool

Impact

Malicious actors can buy multiple loans on behave of someone else's pool without permission

Tools Used

Manual Review

Recommendations

Check if msg.sender does indeed own the specified pool (is the pool.lender)

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.