the function callExternalContract allows the user with the role EXTERNAL_CALLER to call any external contract.
the MembershipFactory is a privileged contract that can call mint and burn on MembershipERC1155 contracts.
this allows the user with the role EXTERNAL_CALLER to tamper with the users MembershipERC1155 tokens.
manual audit
explicitly block function callExternalContract from calling any daoMembershipAddress
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.