The event SetNetPassword does not emit significant information
The SetNetPassword event is triggered when the password is updated. However, it doesn't emit the address that updated the password which is useful for tracking changes
This is a low impact vulnerability. It does not compromise the contract's functionality, but it does reduce transparency and traceability.
Manual code inspection
Update the SetNetPassword event to include the sender's address and possibly the new password hash for better tracking
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.