Snowman::mintSnowman can be called by anyone
High
Likelihood:
always
Impact:
Snowman::mintSnowman can be called by anyone
copy the code in TestSnowmanAirdrop.t.sol and run forge test --mt testNftcanbemintbyanyone -vvv
anyone can mint a snownft
check the msg.sender is SnowmanAirdrop
The mint function of the Snowman contract is unprotected. Hence, anyone can call it and mint NFTs without necessarily partaking in the airdrop.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.