Anyone can call this function and change the password. It should be restricted to only the owner.
Password can be changed multiple times by anyone, there is no limit and no res
malicious users can keep consistently changing the password, making it difficult to know what the password actually is/ disrupt other features from being accessed
Found the vulnerability doing a manual review.
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.