Skip to content

Latest commit

 

History

History
31 lines (16 loc) · 1.03 KB

046.md

File metadata and controls

31 lines (16 loc) · 1.03 KB

moneyversed

medium

Incomplete validation in submitBid function

Summary

The submitBid function may not properly validate if the bid amount is greater than the available collateral, allowing users to submit invalid bids.

Vulnerability Detail

In the TellerV2Context.sol contract, the submitBid function does not properly validate whether the bid amount is greater than the available collateral. This could allow users to submit invalid bids, potentially compromising the integrity of the loan process.

Impact

Potential submission of invalid bids, compromising the integrity of the loan process.

Code Snippet

https://github.com/sherlock-audit/2023-03-teller/blob/main/teller-protocol-v2/packages/contracts/contracts/TellerV2.sol#L272

https://github.com/sherlock-audit/2023-03-teller/blob/main/teller-protocol-v2/packages/contracts/contracts/TellerV2.sol#L303

Tool used

Manual Review

Recommendation

Add validation checks in the submitBid function to ensure that the bid amount is less than or equal to the available collateral.