code-423n4 / 2021-04-vader-findings

1 stars 0 forks source link

`DAO.mapPID_finalised` is never read in the contract, only written #233

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Handle

@cmichelio

Vulnerability details

DAO.mapPID_finalised is never read in the contract, only written. Remove it and show the finalized state in the frontend based on whether the FinalisedProposal event was emitted

0xBrian commented 3 years ago

https://github.com/vetherasset/vaderprotocol-contracts/commit/6f961e6cd159e905ef53a5a067f956d21f8a46ee