The owner(Admin) can update the gracePeriod to a desirable time and as a result, call declare winner and win all the pot which cheats the system everytime.
It is expected that the game time can be updated with any chosen parameters (excluding 0).
The issue with this very easy implementation is that the owner can set the new time and immediately claim the pot winnings.
Likelihood:
This issue would definitely occur as it is evident that the admin has power to cheat the system
Impact:
The impact of this isse is that the admin can win everytime they update the gracePeriod and thereby game the system.
The below test shows how the gracePeriod can be manipulated and the admin steals the winnings everytime.
Listed below are some steps recommended to tackle the issue:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.