updateRegistry is missing the access control which allows anyone to update the registry with malicious control.
updateRegistry is missing the access control to prevent anyone from updating the registry to malicious control.
Malicious actors can update the registry to a malicious contract and misuse it to mint the NFT bypassing the isVerified check.
Manual review.
Add the access control check so only the owner of the contract can update the registry.
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.