
Licence contract's load() function will execute `transferFrom` on an arbitrary contract

Closed this issue · 1 comments

Licence contract is not checking if the assed that is being loaded is supported and will execute transferFrom on any contract address passed as argument.
We should introduce a check by consulting token whitelist before transferring ERC20

duplicate of #547