The getPlayerCards and getDealerCards functions lack access control, allowing any user to call these functions and retrieve the cards of any player or dealer by specifying their address. This violates the principle of data confidentiality, as players should only be able to view their own cards and dealers should only access their own cards.
Unauthorized users can view sensitive game information, such as the cards held by other players and dealers.
Manual
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.