Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Invalid

Missing check in stake function

Summary

No check in the stake function.

Vulnerability Details

There is no check in the stake function to ensure that any user calling the function and passing in a tokenId(to be staked), is actually the owner of this tokenId. As a result, a tokenId owned by one user can be staked by another user who doesn’t own it.

Impact

A user’s token can be staked by anybody.

Tools Used

Manual Inspection

Recommendations

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Incorrect statement

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.