Beginner FriendlyFoundryNFT
100 EXP
View results
Submission Details
Severity: high
Invalid

Anyone can Access the ChangeFeeAddress

Summary

The contract lacks an "onlyOwner" modifier function. Since the contract is using the "onlyOwner" modifier in the "changeFeeAddress" function, anyone could potentially access the "changeFeeAddress" function.

Vulnerability Details

The absence of the "onlyOwner" modifier exposes a critical security vulnerability. Anyone has the ability to change the feeAddress.

Impact

The absence of proper access control could result in a loss of fees, as the fee can be transferred to an unauthorized address.

Tools Used

Manual review

Recommendations

It is highly recommended to add a function modifier "onlyOwner" in the contract to restrict access to sensitive functions.!

Updates

Lead Judging Commences

Hamiltonite Lead Judge about 2 years ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.

Give us feedback!