CVE-2018-19834

HIGH

bombba - Unauthenticated Ownership Takeover via quaker Function

Title source: llm
STIX 2.1

Description

The quaker function of a smart contract implementation for BOMBBA (BOMB), an tradable Ethereum ERC20 token, allows attackers to change the owner of the contract, because the function does not check the caller's identity.

Scores

CVSS v3 7.5
EPSS 0.0093
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
bombba_project/bombba
Published Dec 31, 2019
Tracked Since Feb 18, 2026