Vulnerabilities > CVE-2022-27134 - Incorrect Authorization vulnerability in B1 Eosio Batdappboomx 327C04Cf

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
b1
CWE-863

Summary

EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

Vulnerable Configurations

Part Description Count
Application
B1
1

Common Weakness Enumeration (CWE)