Missing check for owner in setPassword().
msg.sender should be checked as owner before updating to a new password.
Anyone can update and set a new password.
Manual review
check for ownership before saving the new password
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.