No acess control on the RamNFT::mintRamNFT
function.
For a user to get the RamNFT they need to call the Dussehra::enterPeopleWhoLikeRam
function, pay the entrance fee and then mint the RamNFT and it can only be done once. But a user can bypass this by calling the RamNFT::mintRamNFT
function directly.
The user can mint the RamNft without paying the entrance fee, they can mint as much RamNFT as they want, get their RamNFT to be selected as ram and collect the rewards.
Manual analysis
Add acess control to the RamNFT::mintRamNFT
function so it can only be called by the Dussehra
contract.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.