PT-2025-18171 · Unknown · Coresmartcontracts Uniswap

Published

2025-04-29

·

Updated

2025-04-29

·

CVE-2025-25962

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Coresmartcontracts Uniswap versions 3.0 through 3.0
Description The issue allows a remote attacker to escalate privileges via the modifyPosition function. This enables the attacker to gain elevated access, potentially leading to further exploitation.
Recommendations For Coresmartcontracts Uniswap version 3.0, update to version 4.0 to resolve the issue. As a temporary workaround, consider restricting access to the modifyPosition function until the update can be applied.

Exploit

Fix

LPE

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-25962

Affected Products

Coresmartcontracts Uniswap