Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: medium
Valid

Any third party user can overwrite the 0 couple message

Summary

Any third party user can overwrite the 0 couple message

Vulnerability Details

If the user is not has a couple, then it will default to ownerToId[msg.sender] value 0 and can rewrite the message

Impact

A couple may receive the wrong message from a third party

Tools Used

Manual review

Recommendations

Add a check for null value

Updates

Lead Judging Commences

0xnevi Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

finding-write-message-nft-0-id

Medium Severity, This has an indirect impact and influence on the possibility of divorce between soulmates owning the first soulmate NFT id0, leading to permanent loss of ability to earn airdrops/staking rewards.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.