Vulnerability Description
An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that allows an attacker to change the owner of the contract and obtain cryptocurrency for free.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xbornid | Xbornid | <= 2019-05-29 |
References
- https://github.com/smsecgroup/SM-VUL/tree/master/typo-vul-00ExploitThird Party Advisory
- https://github.com/smsecgroup/SM-VUL/tree/master/typo-vul-00ExploitThird Party Advisory
FAQ
What is CVE-2019-15078?
CVE-2019-15078 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The name of the constructor has a typo (wrong case: XBornID versus XBORNID) that all...
How severe is CVE-2019-15078?
CVE-2019-15078 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15078?
Check the references section above for vendor advisories and patch information. Affected products include: Xbornid Xbornid.