code-423n4 / 2021-09-swivel-findings

0 stars 0 forks source link

lack of event emission after sensitive action #122

Closed code423n4 closed 2 years ago

code423n4 commented 2 years ago

Handle

JMukesh

Vulnerability details

Impact

No event was emitted after fee has been updated which prevents the intended data from being observed easily by off-chain interfaces

Proof of Concept

https://github.com/Swivel-Finance/gost/blob/5fb7ad62f1f3a962c7bf5348560fe88de0618bae/test/swivel/Swivel.sol#L402

Tools Used

Recommended Mitigation Steps

add event for updating fee