CVE-2018-12078
Severity:
HIGH
Type:
Unavailable / Other
Publication date:
25/06/2018
Last modified:
03/10/2019
Description
The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
Medium
Vulnerable products and versions
- cpe:2.3:a:polyai_project:polyai:-:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
References to Advisories, Solutions, and Tools
- https://peckshield.com/2018/06/11/tradeTrap/ (Source:MISC)