ZeroHour

CVE-2018-15552

PoC
CVSS 3.1
7.5 high
EPSS
1%p65
Published
()
Modified
Description

The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (which is private, yet predictable and readable by the eth.getStorageAt function). Therefore, it allows attackers to always win and get rewards.

Vendors
theethereumlottery
Products
the ethereum lottery
Weakness
CWE-338
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.