The earnSnow function is designed to allow users to earn 1 Snow token once per week. Because of not setting of s_earnTimer parameter,attacker is able to get 1 NFT without doing staking.
Likelihood:
The exploit is highly likely in real-world conditions due to the fully public access to the earnSnow() function, predictable default state (s_earnTimer == 0)
Impact:
Anyone able to get 1 NFT without staking
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.