s_password can be set by anyone via setPassword().
setPassword() is accessible by anyone. Anyone can change the value of s_password.
Off-chain code or external contracts that rely on s_password being set only by one entity/role are vulnerable to this. This could result in fund loss or protocol being bricked.
Manual review.
Anyone can call `setPassword` and set a new password contrary to the intended purpose.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.