Missing access control on checkList function allows it to be called by any user
The above poc shows that the a user can call the checkList
function and set their status to whatever they like
Users can change/set their status or any user's status at will
Manual Review
Add the onlySanta
modifier to the checkList
function
Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.