What should normally happened is only owner should recieve his failed transfer credits. But since there is no check on msg.sender == _reciever anyone can pass any address.
Likelihood:
Anyone with such small brain as mine will drain this contract dry
Sorry I really suck putting words together
Impact:
Your marketplace is drained dry
withdrawAllFailedCredits allows any user to withdraw another account’s failed transfer credits due to improper use of msg.sender instead of _receiver for balance reset and transfer.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.