Missing check House price's staleness in RAACNFT::mint()
In RAACNFT::mint(), users can transfer some funds to buy one RWA NFT according to this RWA NFT's price.
The problem here is that we get the price from raac_hp.tokenToHousePrice(_tokenId)
. But we miss checking whether this price is staleness. If the price is staleness and less than the actual price, users may buy this RWA with one lower price than expected.
The house price may be staleness. Users may buy this house with one lower price.
Manual
Use the getLatestPrice
interface to get the latest price and the last update timestamp. Check the last update timestamp and make sure the house price is not staleness.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.