No access check in setPassword
function.
Any one call the setPassword
function and change the value of the s_password
variable.
Anyone can change the password stored inside the contract.
Manual review, Ape.
Add checks to see if the sender is the owner of the password or not
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.