Upgraded Q -> M from 143 [1663859521800] #321
Labels
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
duplicate
This issue or pull request already exists
upgraded by judge
Original issue severity upgraded from QA/Gas by judge
Judge has assessed an item in Issue #143 as Medium risk. The relevant finding follows:
2.ETHRegistrarController.register() can pass any "resolver" and "data" parameters , then ETHRegistrarController do "functionCall "
It is possible to pass malicious parameters example :
resolver = baseRegistrar.address, and data = baseRegistrar.register()
then will register a “weird” ens
Recommendation add:
The text was updated successfully, but these errors were encountered: