mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 01:04:30 +00:00
777 B
777 B
CVE-2020-35962
Description
The sellTokenForLRC function in the vault protocol in the smart contract implementation for Loopring (LRC), an Ethereum token, lacks access control for fee swapping and thus allows price manipulation.
POC
Reference
- https://blocksecteam.medium.com/loopring-lrc-protocol-incident-66e9470bd51f
- https://blocksecteam.medium.com/loopring-lrc-protocol-incident-66e9470bd51f
Github
No PoCs found on GitHub currently.