msg.sender is not used as from in transferFrom , a hacker can call these function and manipulate the from and to parameters
it can lead to loss of funds in user accounts
the from parameter should be msg.sender
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.