Impact
An authenticated user can request a pending payment code for an arbitrary coin amount, abandon the Stripe checkout, and then submit that code to the unauthenticated /api/stripe/processed endpoint. The backend allows the code to be accepted without verifying ownership, without confirming that Stripe’s session status is ‘paid’, and without matching the amount charged. As a result the system grants the full credit amount by calling User::addCreditsAtomic(), creating free virtual currency for the attacker. This is an authorization bypass that directly leads to financial loss by draining hosting resources, and it aligns with CWE-345 and CWE-862.
Affected Systems
MythicalLTD’s MythicalDash, versions 3.5.4‑aurora and prior, are affected because the vulnerable GET /api/stripe/process endpoint creates a pending database row and the later /api/stripe/processed route can accept that row without proper ownership or payment validation.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate impact. The EPSS score of less than 1 % suggests that exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog, but the risk remains due to the lack of a current patch. The likely attack vector is a standard HTTP GET request from any host that can reach the MythicalDash server. An attacker who has legitimate credentials can exploit the flow to hijack credits and incur unanticipated costs.
OpenCVE Enrichment