There is no access control forGivingThanks::updateRegistry(address)
, registry contract could be manipulated by anyone.
GivingThanks
uses CharityRegistry
as reference to check verified charities. However, GivingThanks::updateRegistry
is public and able to be changed the reference by anyone else.
CharityRegistry could be manipulated and doner might send money to unverified charities.
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.