moneyversed
high
The liquidateCollateral function does not restrict access to only the lender or the liquidator, potentially allowing unauthorized parties to call the function and claim collateral.
In the TellerV2Context.sol contract, the liquidateCollateral function lacks proper access control, allowing any address to call the function and potentially claim collateral. This could lead to unauthorized liquidation of loans and loss of collateral.
Potential unauthorized liquidation of loans and loss of collateral.
Manual Review
Implement proper access control in the liquidateCollateral function to restrict access to only the lender or the liquidator.