40,000 USDC
View results
Submission Details
Severity: low
Valid

The Escrow's constructor does not check if arbiter address is equal to seller/buyer address

Summary

The Escrow's constructor does not check if arbiter address is equal seller/buyer address.

Vulnerability Details

If the arbiter address would be mistakenly set to one seller or buyer address, the one site can be overprivileged to initiate and resolve dispute to their advantage.

Impact

One site of escrow may be able to initiate and resolve dispute

Tools Used

Manual review

Recommendations

Check if the arbiter address is not equal to seller or buyer address.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.