Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: low
Invalid

No tier prices validation

Summary

There is currently no validation on the tier prices when creating a DAO membership, which any verified user can initiate. This allows malicious actors to set abnormally low tier prices, thereby avoiding platform fees. Since these fees are calculated based on the specified tier price, a near-zero price results in no fees being charged. This loophole allows unauthorized usage of platform resources without the intended payment. Additionally, malicious actors face minimal risk, as they only incur gas fees without risking their own funds.

Vulnerability Details

In the createNewDAOMembership function, there is no minimum check on the tier price.

Impact

The lack of validation enables exploitation of platform resources without payment, affecting revenue and promoting malicious use.

Recommendations

Implement a minimum tier price check in createNewDAOMembership.

Updates

Lead Judging Commences

0xbrivan2 Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Known issue

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!