Due to lack of modifier to check who can call the s_theListCheckOnce, attacker can Dos user by updating thier status to naught hence the wont be able to collect present.
Access Control, Missing modifier
User can lose access to present, Dos
foundry, manual review
add the onlysanta modifier to the checkListOnce function
Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.