updateCountMartenitsaTokensOwner
in MartenitsaToken.sol should be properly access controlled for the protocol to work properly.
Since the function can be called anyone by passing in a proper address
and operation
, user balance of MartenitsaTokens are fully compromised.
User balance of tokens compromised, further logic which is dependant on the logic fails.
Manual Review
Add proper access control for the updateCountMartenitsaTokensOwner
function.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.