All teacher addresses are publicly viewable, creating privacy concerns and potential security risks.
Root cause:
Initial State:
Teacher addresses stored in public array
No access control on viewing addresses
Step 1: Anyone can call getListOfTeachers()
Step 2: Complete list of teacher addresses exposed
Step 3: Addresses can be tracked and targeted
Implications:
Privacy concerns for teachers
Potential for targeted attacks
Social engineering risks
Teacher privacy compromised
Increased risk of phishing attacks
Potential for targeted social engineering
Manual Review
Implement role-based access:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.