Beginner FriendlyFoundryGameFi
100 EXP
View results
Submission Details
Severity: high
Valid

Lack of access control for `updateCountMartenitsaTokensOwner`

Summary

updateCountMartenitsaTokensOwner in MartenitsaToken.sol should be properly access controlled for the protocol to work properly.

Vulnerability Details

Since the function can be called anyone by passing in a proper address and operation, user balance of MartenitsaTokens are fully compromised.

Impact

User balance of tokens compromised, further logic which is dependant on the logic fails.

Tools Used

Manual Review

Recommendations

Add proper access control for the updateCountMartenitsaTokensOwner function.

Updates

Lead Judging Commences

bube Lead Judge over 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

Missing access control

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.