Malicious user can call buyPresent
with address having collected present to get a NFT
A user can monitor addresses that has call collectPresent
function. Then he immediately call buyPresent
function with addresses that just called collectPresent
function. Then he can get a NFT for free.
User can call buyPresest
function to get a NFT for free
foundry
The ```buyPresent`` function can be rewrited like this:
Current implementation allows a malicious actor to burn someone else's tokens as the burn function doesn't actually check for approvals.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.