Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: medium
Invalid

Access control: No checks on who can call the buyPresent function

Summary

As stated in the info regarding to this function, it is expected that this function can only be called by a sender with santaTokens. However, there are no checks in place which enforces this.

Vulnerability Details

Impact

Tools Used

Manual Review

Recommendations

Add a check to ensure that msg.sender has tokens.

Updates

Lead Judging Commences

inallhonesty Lead Judge over 1 year ago
Submission Judgement Published
Invalidated
Reason: Design choice

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.