Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Valid

Attacker can dos user from collecting present by Updating user theListcheckOnce status

Summary

Due to lack of modifier to check who can call the s_theListCheckOnce, attacker can Dos user by updating thier status to naught hence the wont be able to collect present.

Vulnerability Details

Access Control, Missing modifier

Impact

User can lose access to present, Dos

Tools Used

foundry, manual review

Recommendations

add the onlysanta modifier to the checkListOnce function

Updates

Lead Judging Commences

inallhonesty Lead Judge almost 2 years ago
Submission Judgement Published
Validated
Assigned finding tags:

Access Control on checkList()

Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.