Hawk High

First Flight #39
Beginner FriendlySolidity
100 EXP
View results
Submission Details
Severity: low
Valid

Missing Logic

Summary
The addTeacher() lacks some missing logic where the principal can add themselves as the teacher

Vulnerability Details
if the principal is malicious or compromised, they can themselves as the teacher since they have access control

Impact
the impact may be low, since adding themselves may just create confusion and no direct impact

Tools Used

manual review

Recommendations
consider adding the logic that even if the principal has the sole acces control, they cannot add themselves as the teacher

Updates

Lead Judging Commences

yeahchibyke Lead Judge 26 days ago
Submission Judgement Published
Validated
Assigned finding tags:

principal can become teacher

Principal can add themselves as teacher and share in teacher pay upon graduation

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.