Anyone can buy a present for a user as opposed to the intended functionality
In the buy present function above, there is no logic to ensure that the function can be called by a naughty user only as stated in the developer notice above
Manual Review
Add the following line of code to the buyPresent
function
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.