CVE-2020-35962 Information
Jun 07, 2022
cve
Description
The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC) an Ethereum token lacks access control for fee swapping and thus allows price manipulation.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
https://etherscan.io/address/0x4b89f8996892d137c3de1312d1dd4e4f4ffca171 https://blocksecteam.medium.com/loopring-lrc-protocol-incident-66e9470bd51f
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.5
Share on: