mintSnowman is called from SnowmanAirdrop.sol to mint the amount of ERC721 equivielnt Snowman of the snow ERC20 a claiming address holds.
mintSnowman lacks caller checks ensuring only the SnowmanAirdrop.sol can call this function. A user can call this to mint as many snowman ERC721 as they like without owning any snow or passing the signature/merkle requirement.
Likelihood:
High
Impact:
Could cause loss of funds if the NFT is used to claim Snow tokens.
The mint function of the Snowman contract is unprotected. Hence, anyone can call it and mint NFTs without necessarily partaking in the airdrop.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.