updateUserBoost does not have access control, allowing anyone to update a user's boost.
In BoostController.sol, updateUserBoost allows updating boost value for a user in a specific pool
The function however does not have access control, allowing anyone to update a user's boost.
Anyone can update any user's boost, and such a function can be misused.
Manual Review
Add a form of access control to the function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.