New players can be blocked from entering the raffle.
After two players have been refunded, the duplicate address checker will always pass as there will be two 0 addresses in the players array.
Doesn't allow raffle to function as intended and allow new players. Can lead to loss of funds where a genuine player enters and malicious actor performs DOS on contract as select winner will not be able run with less than 4 players.
Manual review
Delete addresses from players array after refund instead of changing to 0 address, will need to use pop instead of built in delete.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.