Attacker could register adress with malicious behaviour pretending that is an address of a pool, as providing a self-destructing contract. That will cause future errors if the attacker gains MANAGER_ROLE.
Instead of relying on onlyRole modifier you can add additional check.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.