mediumLogic errorEVM-Solidity
Phi: Lack of data validation when users are claiming their art allows malicious user to bypass signature/merkle hash to provide unapproved `ref_`, `artId_` and `imageURI`
- Payout
- $0
- Protocol
- Phi
- Disclosed
- Oct 7, 2024
- Source
- code4rena
The PhiFactory contract fails to cryptographically bind key parameters to the claim validation process, allowing users to inject arbitrary values during art claiming. Specifically, the referral address, art ID, and image URI are not included in the Merkle proo …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-08-phi-findings/issues/73
- https://github.com/code-423n4/2024-08-phi-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.