sherlock-audit / 2023-10-perennial-judging

11 stars 7 forks source link

tvdung94 - Malicious users might grief other users by forcing execute orders #47

Closed sherlock-admin2 closed 1 year ago

sherlock-admin2 commented 1 year ago

tvdung94

medium

Malicious users might grief other users by forcing execute orders

Summary

Malicious users might grief other users by forcing execute orders.

Vulnerability Detail

The fact that users can freely trigger order execution for others might introduce an opportunity for malicious users to grief others. Consider this scenario:

Manual Review

Recommendation

Consider adding an option for users to allow/disallow other users to trigger their placed orders.

sherlock-admin2 commented 1 year ago

2 comment(s) were left on this issue during the judging contest.

panprog commented:

invalid, orders are expected to be executed as soon as their condition is satisfied, it is not expected that only the user himself can execute it, contrary, it's the keepers who execute orders as soon as possible

tsvetanovv commented:

Low