Anyone can set a new password because of missing owner check in setPassword function.
There is no owner check in setPassword function.
Contract core functionality is broken. Anyone can override owner's password.
Manual review.
Insert an owner check in setPassword function.
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.