highAccess controlEVM-Solidity
Munchables: Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens
- Payout
- $0
- Protocol
- Munchables
- Disclosed
- Jun 21, 2024
- Source
- code4rena
Munchables' LockManager exposed a public `lockOnBehalf` function lacking access control, letting any caller donate tokens or ETH on behalf of any other user. Because the call recomputes and extends the recipient's lock duration, an attacker could repeatedly ze …
Similar reports
- No close matches yet.
References
- https://github.com/code-423n4/2024-05-munchables-findings/issues/165
- https://github.com/code-423n4/2024-05-munchables-findings
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.