Project

One World
NFTDeFi
15,000 USDC
View results
Submission Details
Severity: medium
Invalid

Tiers power could be changed in tiers, which already have minted nft

Summary

User with role EXTERNAL_CALLER could change power of tiers, which already have minted nft, which could not be ok for already joined users to this tier.

Vulnerability Details

Yes, user with role EXTERNAL_CALLER is trusted, but he allowed to change tier configuration and could change value (power) of tier, when tier has minted nft. Users in this tier maybe dont agree with new power value, but they could not do anything.

Impact

User join to tier, and power of this tier is ok for him. But User with role EXTERNAL_CALLER update tier configuration and power of tier has changed. And new value is not ok for user, but he could not do anything. He also could not return tokens, which were transfered from his balance for joining pool (exit for tier).

Tools Used

Manual review

Recommendations

Denied user with role EXTERNAL_CALLER change tiers power, if tier have minted nfts.

Updates

Lead Judging Commences

0xbrivan2 Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice
0xbrivan2 Lead Judge about 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!