Beginner FriendlyFoundryGameFi
100 EXP
View results
Submission Details
Severity: high
Valid

Anyone can update the count of martenitsaTokens for a specific address

Summary

Anyone can change the count of martenitsaTokens for specific address

Vulnerability Details

updateCountMartenitsaTokensOwner - Function to update the count of martenitsaTokens for a specific address.

There are no checks that you are updating only your number and whether you really own that many tokens.

Impact

Increase your own number of tokens or reduce someone else's number

Tools Used

Manual

Recommendations

Make the onlyOwner or check whether the user really has so many tokens

Updates

Lead Judging Commences

bube Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Missing access control

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.