Lack of access control in checkList
function.
Lack of access control can cause manipulating status.
This function should be callable only by santa.
Scenario:
Attacker can change his own status to nice and he will be rewarded with present.
Manual Review
Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.