Unlimited Health Tokens can be minted because anyone can manipulate the MartenitsaToken count.
Anyone can update the count of MartenitsaToken due to lack of access specifier/modifier in the MartenitsaToken.sol::updateCountMartenitsaTokensOwner()
function
Through this any user can increase their count of MartenitsaToken
without actually buying the token! This in combination with the MartenitsaMarketplace.sol::collectReward()
, infinte Health Tokens can be minted.
Loss of Funds/ Severe Disruption of protocol.
Manual Review
Relevant modifiers should be used for securing the MartenitsaToken.sol::updateCountMartenitsaTokensOwner()
function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.