DittoETH

Ditto
DeFiFoundryOracle
55,000 USDC
View results
Submission Details
Severity: high
Invalid

Anyone can modify the yields.

Summary

Anyone can modify the yields.

Vulnerability Details

This means that anyone can modify yields, and gain more than set by authenticated admins.

https://github.com/Cyfrin/2023-09-ditto/blob/a93b4276420a092913f43169a353a6198d3c21b9/contracts/facets/YieldFacet.sol#L41C1-L73C6

Impact

Loss of Yields

Tools Used

Manual Review

Recommendations

Create a Role Based Access Control for admins

Updates

Lead Judging Commences

0xnevi Lead Judge
over 1 year ago
0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.