durov - Review authors should be able to archive and restore reviews from any address that belongs to the profile #318
Labels
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
durov
Medium
Review authors should be able to archive and restore reviews from any address that belongs to the profile
Summary
In EthosReview.sol authors of reviews can archive and restore reviews only from the original address, even though the profile can have multiple address registered to it.
https://github.com/sherlock-audit/2024-10-ethos-network/blob/main/ethos/packages/contracts/contracts/EthosReview.sol#L287-L332
Root Cause
Checks in EthosReview:300, EthosReview:321
Internal pre-conditions
No response
External pre-conditions
No response
Attack Path
No response
Impact
Authors can't archive or restore their reviews from different addresses belonging to the same profile, even though they can edit their reviews from different addresses.
PoC
No response
Mitigation
Let authors archive or restore their reviews from any address that belongs to their profile.
The text was updated successfully, but these errors were encountered: