Missing owner check when setting password
Anyone can set the password as the setPassword function does not check if the caller is the owner
Password can be set to a value different than what the owner wants.
Manual review
Add a check that the msg.sender is the owner
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.