Beginner FriendlyFoundryBridge
100 EXP
View results
Submission Details
Severity: high
Valid

use of arbitrary from in transferFrom

Summary

msg.sender is not used as from in transferFrom , a hacker can call these function and manipulate the from and to parameters

Vulnerability Details

Impact

it can lead to loss of funds in user accounts

Tools Used

Recommendations

the from parameter should be msg.sender

Updates

Lead Judging Commences

0xnevi Lead Judge about 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

depositTokensToL2(): abitrary from address

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.