code-423n4 / 2021-05-88mph-findings

0 stars 0 forks source link

lack of zero address validation in constructor #13

Open code423n4 opened 3 years ago

code423n4 commented 3 years ago

Handle

Jmukesh

Vulnerability details

Impact

due to lack of zero address validation, there is chance of loosing funds

Proof of Concept

https://github.com/code-423n4/2021-05-88mph/blob/main/contracts/rewards/dumpers/Dumper.sol

https://github.com/code-423n4/2021-05-88mph/blob/main/contracts/rewards/dumpers/OneSplitDumper.sol

Tools Used

manual review

Recommended Mitigation Steps

add zero address check

ZeframLou commented 3 years ago

We're fine with this