All reports
mediumAccess controlEVM-Solidity

Revert Lend: User might execute `PositionToken` of token set by previous token owner

Payout
$0
Protocol
Revert Lend
Disclosed
May 22, 2024
Source
code4rena

A logic flaw in Revert Lend's `AutoRange` contract allows position configuration settings to persist across NFT position transfers without validation. When a token owner sets parameters via `configToken()`, the values are stored in a mapping indexed solely by …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.