Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Invalid

03-The `refund` function, which allows players to refund their money early at any time before the end of the match, does not follow business logic

Summary

The refund function, which allows players to refund their money early at any time before the end of the match, does not follow business logic

Impact

This would result in players being able to refund their refunds and withdraw from the tournament at any time at the end of the sweepstakes tournament, which could easily be exploited by an attacker for backdoor operations.

Tools Used

Manual Review

Recommendations

It is suggested that a restriction be placed on this function to only allow refunds for a certain period of time before the start of the draw. Refunds are not allowed after the start of the contest.

Updates

Lead Judging Commences

patrickalphac Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: User experience and design improvement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.