4darsh-Dev / DecenTrade

DecenTrade is a decentralized digital marketplace built on the Ethereum blockchain, enabling secure and transparent transactions for digital assets.
https://decentrade.vercel.app
MIT License
14 stars 62 forks source link

[Bug]: Critical Security Vulnerability: Potential NFT Theft Through Inadequate Title Management and Ownership Verification #150

Open adityajha2005 opened 4 weeks ago

adityajha2005 commented 4 weeks ago

Is there an existing issue for this?

What happened?

A significant vulnerability has been discovered in the DecentradeMarketplace smart contract, which enables malicious actors to alter NFT ownership due to deficiencies in title management and verification processes. The primary concerns are as follows:

Title Manipulation: There is an absence of validation for unique titles during redeployments, which permits the existence of duplicate listings. Ownership Verification Deficiencies: There are insufficient checks for ownership prior to listing and inadequate validation of operators. State Management Issues: There is a potential for race conditions, incomplete state cleanup, and a lack of event logging for changes in title.

Add ScreenShots

No response

What browsers are you seeing the problem on?

No response

Record

github-actions[bot] commented 4 weeks ago

You've successfully raised your issue, We'll get back to you soon. Don't forget to star⭐ the Repo.

4darsh-Dev commented 3 weeks ago

assigned to you @adityajha2005 , propose your changes, and go through contributing guidelines,

adityajha2005 commented 3 weeks ago

@4darsh-Dev I've submitted the PR. Let me know if any adjustments are needed.

4darsh-Dev commented 2 weeks ago

Gentle Reminder 🚨🚨 GSSoC-Ext 24 is going to complete in 2 Days. ' Complete your assigned Issues and PR reviews before time to get Points on Leaderboard. ' It was a great experience working with you all, Don't forget to ⭐ star the Repo (only 12 with 62 forks 💔) . Thanks💗 for your valuable contributions!

4darsh-Dev commented 2 weeks ago

Gentle Reminder 🚨🚨 PA and Mentor nominations have been started for GSSoC-Ext 2k24. ' Do share your experiences and connect on Socials. ' It was a great experience working with you all Thanks💗 for your valuable contributions!