CVE-2018-13041
Last modified
CVE-2018-13041 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linktoken Project | Linktoken | All versions |
References
- https://github.com/dwfault/AirTokens/blob/master/Link_Platform__LNK_/mint%20integer%20overflow.mdExploit, Third Party Advisory
- https://github.com/dwfault/AirTokens/blob/master/Link_Platform__LNK_/mint%20integer%20overflow.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-13041?
How severe is CVE-2018-13041?
How do I fix CVE-2018-13041?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13034Directory traversal in Jester web framework 0.2.0 allows rem…
- CVE-2018-13037An issue was discovered in jpeg-compressor 0.1. The bmp_load…
- CVE-2018-13038OpenSID 18.06-pasca has an Unrestricted File Upload vulnerab…
- CVE-2018-13039OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS)…
- CVE-2018-1304The URL pattern of "" (the empty string) which exactly maps …
- CVE-2018-13040OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerabi…
- CVE-2018-13042The 1Password application 6.8 for Android is affected by a D…
- CVE-2018-13043scripts/grep-excuses.pl in Debian devscripts through 2.18.3 …
- CVE-2018-13045SQL injection vulnerability in the "Bazar" page in Yeswiki C…
- CVE-2018-13049The constructSQL function in inc/search.class.php in GLPI 9.…
- CVE-2018-1305Security constraints defined by annotations of Servlets in A…
- CVE-2018-13050A SQL Injection vulnerability exists in Zoho ManageEngine Ap…
Are you affected by CVE-2018-13041?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
