Neither contract validates that match numbers are within the expected range (0 to NUM_MATCHES - 1).
Functions like setResult
, confirmPredictionPayment
, and setPrediction
accept any uint256 as a match number.
Out-of-bounds array access or storage of predictions for non-existent matches.
Add input validation for match numbers:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.