DatingDapp

First Flight #33
Beginner FriendlyFoundrySolidityNFT
100 EXP
View results
Submission Details
Severity: low
Invalid

Data Exposure and Privacy- We can see yho liked who!

Summary

There is no security risk, but in the contract LikeRegistry having the mapping likes and matches does expose the internal relationship - example, who has liked whom etc.

Vulnerability Details

showing the mapping of likes and matches to everyone.

Impact

Data Exposure and Privacy of the informatin from the app: Users might assume that certain interactions or relationships are private or not easily accessible to others. Exposing such data might lead to privacy concerns or misus.

Tools Used

Manual review

Recommendations

Having this mapping as private and create custom getters.

Updates

Appeal created

n0kto Lead Judge 5 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity
Assigned finding tags:

Informational or Gas

Please read the CodeHawks documentation to know which submissions are valid. If you disagree, provide a coded PoC and explain the real likelyhood and the detailed impact on the mainnet without any supposition (if, it could, etc) to prove your point.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.