The UBSexToken() function of a smart contract implementation for Business Alliance Financial Circle (BAFC), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function is public (by default) and does not check the caller's identity.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-12-31 08:15
Updated : 2020-01-14 05:32
NVD link : CVE-2018-19830
Mitre link : CVE-2018-19830
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
business_alliance_financial_circle_project
- business_alliance_financial_circle