Description:Description\
On deposit in the SingelTokenVirtualRewarderUpgradeable.sol file, the tokenId is not verified which can lead to balance of non-existent token be increased.
Attack Scenario\
The attack path is from the ManagedNFTManagerUpgradeable.sol:onAttachToManagedNFT to CompoundVeFNXManagedNFTStrategyUpgradeable.sol:onAttach to SingelTokenVirtualRewarderUpgradeable.sol:depositAttachments
Github username: @agbanusi Twitter username: -- Submission hash (on-chain): 0xb22d944d6c8eea7d122a50327642c5950e81a09c2a1b9f14c501f537e6a5bafa Severity: medium
Description: Description\ On deposit in the
SingelTokenVirtualRewarderUpgradeable.sol
file, thetokenId
is not verified which can lead to balance of non-existent token be increased.Attack Scenario\ The attack path is from the
ManagedNFTManagerUpgradeable.sol:onAttachToManagedNFT
toCompoundVeFNXManagedNFTStrategyUpgradeable.sol:onAttach
toSingelTokenVirtualRewarderUpgradeable.sol:deposit
Attachmentshttps://github.com/hats-finance/Fenix--0x9d7765a7ebd5b6322a30797a44a5428531970d3d/blob/353c8e8e24454336e805e5c0e11e4e9ae1491d03/contracts/nest/ManagedNFTManagerUpgradeable.sol#L176
https://github.com/hats-finance/Fenix--0x9d7765a7ebd5b6322a30797a44a5428531970d3d/blob/353c8e8e24454336e805e5c0e11e4e9ae1491d03/contracts/nest/CompoundVeFNXManagedNFTStrategyUpgradeable.sol#L79
https://github.com/hats-finance/Fenix--0x9d7765a7ebd5b6322a30797a44a5428531970d3d/blob/353c8e8e24454336e805e5c0e11e4e9ae1491d03/contracts/nest/SingelTokenVirtualRewarderUpgradeable.sol#L121