s_theCheckListOnce is a state variable that should only be updated by santa himself but due to missing modifier, any user or attacker can call the function and update the state. Attacker/user can then proceed to collect present
Access control
Missing modifier allows set their s_theCheckListOnce status buy themselves and claim present
foundry, manual review
should add the onlysanta modfier
Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.