Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Valid

Not checking if the challenger owns a rapper

Summary

The challenger can challenge without any token, just selecting an existing _tokenId with high states. Stats can be checked publicly. There is no check if the challenger owns the Rapper.

Vulnerability Details

Impact

Tokens from the defender are at risk. Anyone can simply stole them.

Tools Used

Manual review, VSCode

Recommendations

Check if the challenger owns the token before continuing the execution.

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Challenger can use any nft to battle - not necessarily theirs

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.