The Owned smart contract implementation for Aurora IDEX Membership (IDXM), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. A new owner can subsequently modify variables.
References
| Link | Resource |
|---|---|
| https://medium.com/@jonghyk.song/aurora-idex-membership-idxm-erc20-token-allows-attackers-to-acquire-contract-ownership-1ff426cee7c6 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-05-03 04:29
Updated : 2019-10-03 00:03
NVD link : CVE-2018-10666
Mitre link : CVE-2018-10666
JSON object : View
Products Affected
auroradao
- idex_membership
CWE
