Impact
AVideo is vulnerable due to missing authorization example of CWE‑345. The flaw, tied to commit c3edcc274c389816d434acadac07ee78eaf330c1, fails to validate ad impressions, allowing any authenticated user to submit arbitrary label values when recording ad impressions. When the label 'start' is submitted, the application blindly credits the corresponding campaign video owner's YPTWallet, without verifying that an ad was actually shown – effectively granting unverified wallet credits. This results in uncontrolled wallet credit inflation that can be abused to fabricate revenue and may lead to significant financial loss for the service provider or other stakeholders.
Affected Systems
The vulnerability affects installations of the AVideo platform that include the AD_Server/log.php plugin before the patch associated with commit c3edcc274c389816d434acadac07ee78eaf330c1. Any user logged into such a system the application.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV, so current exploit probability data a legitimate user session and a simple POST request to log.php, making the attack path straightforward for potential impact of unauthorized wallet credit accumulation makes this a serious threat that can erode trust and revenue streams.
OpenCVE Enrichment