Impact
AVVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross‑site scripting vulnerability in the YPTWallet plugin. User‑supplied CryptoWallet values are base64‑encoded but not HTML‑escaped before storage in a wallet_log.information entry. When an administrator later opens pendingRequests.php to review withdrawal requests, the stored markup is executed in the admin’s browser session, permitting the attacker to perform administrative actions via same‑origin fetch requests.
Affected Systems
The flaw resides in the AVideo platform, provided by WWBN, specifically in the YPTWallet plugin as shipped in the main branch. The affected code can be found in commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific version range is listed; however, any installation that includes this commit or later without the patch is impacted. The vendor is WWBN and the product is AVideo, database.
Risk and Exploitability
This issue carries a CVSS score of 9.3, indicating critical severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to supply a an administrator views the pending withdrawal page; the attack vector is therefore internal to the administrative interface but the initial input can be supplied externally if the plugin accepts user input from outside the protected area. Attackers can achieve privilege escalation to any administrative function that relies on same‑origin requests, potentially compromising the entire platform.
OpenCVE Enrichment