The user should buy the NFTs that have the same ID they enter
In the buy function when users enter the listing_ID they can get a diffrent NFTs not the one they want because we use tokeID in listing
Likelihood:
Reason 1: Every time users try to buy an NFT they will face this problem
Reason 2: Easy to trigger because the functions are external and commonly used.
Impact:
Impact 1: Buyer gets NFTs that are not what they pay for
Impact 2: Marketplace counters and metrics become inconsistent, causing UI errors and potential reporting/fraud issues.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.