The contract defines an owner
variable that is not used in any access control checks or logic. Instead, it should use a proper access control mechanism to restrict critical functions to the owner.
Anyone can call updateRegistry() to change CharityRegistry's admin
manual
Likelyhood: High, anyone can change it at anytime Impact: High, can bypass the verification process
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.