The checkList has no OnlySanta Modifier and thus everyone can set random status for random user
If someone is set to Extra Nice or Nice, a malicious actor can set the user back to Naughty and user receives no NFT
Nice or Extra Nice users lost possibility to mint NFTs
Foundry / Manual Review
Add onlySanta modifier to function
Anyone is able to call checkList() changing the status of a provided address. This is not intended functionality and is meant to be callable by only Santa.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.