In GivingThanks.sol, if this function is not restricted to onlyowner modifier or msg.sender requirement, anyone can update address as this is a public function.
Anyone/malicious actor can updateRegistery
and then call donate
function which will lead to loss of funds
Also it'll impact the integrity & trust.
Manual Review
Use OpenZeppelin’s Ownable.sol for Admin Management.
Or Use Require Check.
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.