The mint() functions retrieve house prices from an external contract (raac_hp). However, they lack stale price detection and min/max price validation, which could lead to incorrect NFT pricing, exploitation, and unfair transactions.
The function fetches the house price; however, there is no check to ensure that the price has been recently updated. If the price is outdated or manipulated, users may overpay or underpay for NFTs.
Users may buy NFTs at incorrect prices due to outdated pricing.
Manual Review
Implement a Stale Price Check
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.