There is no check of caller's status in buyPresent function. Anyone can call it.
As in description, This function is only be callable by someone who is naughty. But there is no status check in this function
Anyone with any status can call buyPresent function
Foundry
adding naughty status check of msg.sender in this function
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.