Description: The GivingThanks::updateRegistry function has no access control, allowing anyone to change the registry address to any value.
Impact:
Complete system compromise possible
Attacker can redirect donations to unverified addresses
Loss of funds for donors
Proof of Concept:
Recommended Mitigation:
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.