CVE-2018-19830
Summary
| CVE | CVE-2018-19830 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-31 16:15:00 UTC |
| Updated | 2023-11-07 02:55:00 UTC |
| Description | The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's identity. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Business Alliance Financial Circle Project | Business Alliance Financial Circle | - | All | All | All |
| Application | Business Alliance Financial Circle Project | Business Alliance Financial Circle | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SmartContractSecurity/README.md at master · SmartContractResearcher/SmartContractSecurity · GitHub | github.com | ||
| SmartContractSecurity/README.md at master · SmartContractResearcher/SmartContractSecurity · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.