The setPassword
function can be called by any user.
The setPassword
function doesn't have any access control that prevents other users from setting the newPassword.
Anyone can set the s_password
to any string that they want.
vscode
Add a modifier to the setPassword
function:
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.