enterRaffle function param newPlayers address array doesn't take into account if zero address is given.
enterRaffle function allows zero address to be entered into the raffle, there is no modifier to stop this.
If the zero address was to be selected as a winner then the 80% of the contract funds would be lost as well as the NFT.
or If user accidentally entered using zero address their entering fee would be lost in the case they wanted to withdraw.
Manual Review
Funds are locked to no one. If someone gets the refund issue, they also got this issue. IMPACT: High Likelihood: High
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.