function
updateRegistry
can be called by anybody, no restriction in place.
Anybody can call the function and change registry address.
If an attacker calls the function, it can change the address to a malicious contract.
ETH won't be donated to registry address as intended.
Manual Review
Add restriction to the function, onlyOwner
.
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.