transferCard should be done after treasury is updated. #35
Labels
1 (Low Risk)
bug
Something isn't working
Resolved
Used when a fix has been implemented.
sponsor confirmed
Handle
0xImpostor
Vulnerability details
Impact
When the current owner of the card is still the new owner of the card,
transferCard
is called before the treasury is updated. While this does not currently pose a risk, it is not aligned with best practices of check-effect-interations and opens your code to a potential re-entrancy attack in the future.Tools Used
Manual analysis
Recommended Mitigation Steps
The text was updated successfully, but these errors were encountered: