Access-control vulnerability in EOSIO batdappboomx v327c04cf smart contract allows remote attackers to win cryptocurrency without paying ticket fee via `transfer` function.

Access-control vulnerability in EOSIO batdappboomx v327c04cf smart contract allows remote attackers to win cryptocurrency without paying ticket fee via `transfer` function.

CVE-2022-27134 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

Learn more about our Web Application Penetration Testing UK.