CVE-2018-12454
17.06.2018, 12:29
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, generates a random value with publicly readable variables such as the current block information and a private variable (which can be read with a getStorageAt call). Therefore, it allows attackers to always win and get rewards.
Vendor | Product | Version |
---|---|---|
1000guess | 1000_guess | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration