Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qvr-f99m-rpch

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency. (Increasing the total supply by using 'doAirdrop' ignores the hard cap written in the contract and devalues the token.)

The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency. (Increasing the total supply by using 'doAirdrop' ignores the hard cap written in the contract and devalues the token.)

EPSS

Процентиль: 41%
0.00193
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

The doAirdrop function of a smart contract implementation for Primeo (PEO), an Ethereum token, does not check the numerical relationship between the amount of the air drop and the token's total supply, which lets the owner of the contract issue an arbitrary amount of currency. (Increasing the total supply by using 'doAirdrop' ignores the hard cap written in the contract and devalues the token.)

EPSS

Процентиль: 41%
0.00193
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-330