Impact
The vulnerability exists in the AVideo YPTWallet plugin within the saveBalance.php script. It is a CSRF flaw that allows an attacker to alter any wallet balance without authentication checks beyond the victim's session cookie. An attacker can embed a malicious form in a web page that, when loaded by an administrator, sends a forged POST request and sets the target user’s balance to an arbitrary value, potentially draining or inflating funds.
Affected Systems
The affected product is WWBN's AVideo platform. All installations that include the YPTWallet plugin with the vulnerable commit c3edcc274c389816d434acadac07ee78eaf330c1 are impacted. No specific version number is supplied, so any deployment containing that commit is considered vulnerable.
Risk and Exploitability
The reported CVSS score of 7.1 indicates high severity. The exploitable vector relies on administrators visiting a crafted page, leveraging their session cookie, which is a well‑known and easily executed CSRF attack. With no EPSS data, the exact likelihood of exploitation is unknown, and the CVE is not listed in the KEV catalog. The risk is that an attacker could induce large financial losses for the organization or its users.
OpenCVE Enrichment