Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: low
Invalid

Uninformative Event: setPassword gives no context

Summary

The event PasswordSet does not contain any information about the user that set the password. This makes it hard to track who set the password.

Vulnerability Details

Impact

It's harder to map passwords updates off-chain.

Tools Used

Recommendations

  • Do not update the contract storage if the new password is identical to the current one.

  • Add the owner address and optionally the value of the new encrypted password .

Updates

Lead Judging Commences

inallhonesty Lead Judge
over 1 year ago
inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.