In RToken.sol
in transferFrom
function Malicious user will give sender address as user address and recipient address as own address. Using this malicious user will be able to steal money from other user.
In RToken.sol
in transferFrom
function Malicious user will give sender address as user address and recipient address as own address. Using this malicious user will be able to steal money from other user.
Users will lost his own money.
Manual review
In RToken.sol
in transferFrom
function use sender address equal to msg.sender
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.