RustFund

First Flight #36
Beginner FriendlyRust
100 EXP
View results
Submission Details
Severity: low
Invalid

Missing creator access control to manage campaign settings

Summary

Once a creator creates a campaign, he has no way of changing its name and description.

Vulnerability Details

The project's readme states "(Creator) Has exclusive rights to manage their campaign settings". However, the only way he can set the campaigns name and description are in fund_create(). There is no access control to update these settings.

Impact

Low. It does affect the protocols solvency other than if a mistake was made in the settings it migt attract less funding from users.

Tools Used

Manual review

Recommendations

Add a function to modify the campaigns name and description.

Updates

Lead Judging Commences

bube Lead Judge
5 months ago

Appeal created

bube Lead Judge 5 months ago
Submission Judgement Published
Invalidated
Reason: Non-acceptable severity

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.