Core Contracts

Regnum Aurum Acquisition Corp
HardhatReal World AssetsNFT
77,280 USDC
View results
Submission Details
Severity: low
Valid

Lack of access control in recordVote function

Summary

veRAACToken::recordVote lacks any kind of access control modifiers, anyone can change the _hasVotedOnProposal status of any other user to true.

Impact

Unrestricted access to setter functionality.

Tools Used

Manual review.

Recommendations

Add access control for the role that is meant to set this state variable.

Updates

Lead Judging Commences

inallhonesty Lead Judge 2 months ago
Submission Judgement Published
Validated
Assigned finding tags:

veRAACToken::recordVote lacks access control, allowing anyone to emit fake events

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.