20,000 USDC
View results
Submission Details
Severity: high
Valid

buyLoan doesn't check that msg.sender is pool owner

Summary

buyLoan doesn't check that msg.sender is pool owner. Anyone can provide pool, that exist and he will be set as loan owner.

Vulnerability Details

When loan is on auction, then anyone can call buyLoan. You need to provide loanId and poolId. Pool will be decreased with debt that should be provided. There is no check in function, that msg.sender is owner of pool. And in the end it is set as lender of loan.

This allows attacker to use existing pool with funds to buy loan, but owner of that pool will not be able to use it. Looks like attacker will not be able to withdraw these funds, but owner of pool will definitely lose his funds.

Impact

owner of pool will lose his funds

Tools Used

VsCode

Recommendations

Check that msg.sender is owner of pool.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.