Mystery Box

First Flight #25
Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: low
Valid

Incorrect Reward Values

Summary

The reward values for Silver Coin and Gold Coin are incorrect in openBox().

Vulnerability Details

The values for the Silver Coin and Gold Coin rewards in openBox() do not match the intended value specified in the constructor. Here the values for each coin are twice the amount originally declared.

Impact

This will result in users that win either coin leaving with twice the value for each than was originally intended.

Tools Used

Manual Review

Recommendations

When pushing a reward to rewardsOwned() reference it from rewardPool() by reading the index of the respective reward.

Updates

Appeal created

inallhonesty Lead Judge about 1 year ago
Submission Judgement Published
Validated
Assigned finding tags:

The rewards in constructor are different from the rewards in openBox

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!