Mystery Box

First Flight #25

Mystery Box

Beginner FriendlyFoundry
100 EXP
Submission Details
Severity: medium
Valid

DoS vulnerability through array bloating and reward management inconsistencies due to array element deletion flaw in `Mysterybox::transferReward`

Updates

Appeal created

InAllHonesty Lead Judge 5 days ago
Submission Judgement Published
Validated
Assigned finding tags:

A user can poison the `rewardsOwned` of another user via `transferReward` of an empty reward index

Support

FAQs

Can’t find an answer? Join our Discord or follow us on Twitter.