CVE-2018-17882 Information

Description

An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB) an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://etherscan.io/address/0x4daa9dc438a77bd59e8a43c6d46cbfe84cd04255code https://github.com/GreenFoxy/Smart-contract-Vulnerabilities/blob/master/BattleToken.md

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: