Summary
When the number of students is excessively large, calling expel by the principal may result in a DOS (Denial of Service) attack.
Vulnerability Details
To find a specific student, the system will iterate through all students! When the number of students becomes too large, this may lead to a DOS attack.
Since the system could be used by dozens or even hundreds of schools, each with thousands of students, a DOS attack is a real possibility!
Impact
Expelling a student will incur a large amount of gas.
Due to the large number of students, this could potentially lead to a DOS attack.
POC
Not written.
Recommendations
It is recommended to use a mapping to retrieve the specific student!
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.