The function configurePass doesn't check if the collection has been already created. As a result, the supply is reset even though tokens have already been minted.
Likelihood:
the organizer make the mistake of configuring a pass that already exists
Impact:
reset the supply to 0
modify the parameter of the collection (max supply, price)
We need to verify that the collection id has not been used yet, so we need to monitor which collection has been created over time.
PS : Sorry for the explanation, that's a last minute submission :(
This is not acceptable as high because any attack vectors related to organizer trying to milk ETH from participants is voided by the fact that the organizer is trusted.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.