Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Kenun99

#36505of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2022-18242
7.5
2022-05-12
Eosio · Eosio · CVE-2022-27134
**Name of the Vulnerable Software and Affected Versions** EOSIO batdappboomx version v327c04cf **Description** The issue concerns an Access-control vulnerability in the `transfer` function of the smart contract. This vulnerability allows remote attackers to win cryptocurrency without paying the ticket fee by exploiting the `std::string memo` parameter. **Recommendations** For EOSIO batdappboomx version v327c04cf, consider disabling the `transfer` function until a patch is available to prevent exploitation. Restrict access to the `std::string memo` parameter in the affected smart contract to minimize the risk of unauthorized cryptocurrency wins.