The test 'GivingThanks::testCannotDonateToUnverifiedCharity' proves () that the 'CharityRegistry::verifyCharity' function does not check if the charity is verified by the admin, only if the charity has been registered.
Foundry, Manual Code Review
Likelyhood: High, the function returns registered charities instead of verified ones. Impact: High, Any charities can be registered by anyone and will be declared as verified by this function bypassing verification.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.