Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.
Published: 2026-09-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Wallet Credit Addition
Action: Patch immediately
AI Analysis

Impact

AVideo is vulnerable due to missing authorization example of CWE‑345. The flaw, tied to commit c3edcc274c389816d434acadac07ee78eaf330c1, fails to validate ad impressions, allowing any authenticated user to submit arbitrary label values when recording ad impressions. When the label 'start' is submitted, the application blindly credits the corresponding campaign video owner's YPTWallet, without verifying that an ad was actually shown – effectively granting unverified wallet credits. This results in uncontrolled wallet credit inflation that can be abused to fabricate revenue and may lead to significant financial loss for the service provider or other stakeholders.

Affected Systems

The vulnerability affects installations of the AVideo platform that include the AD_Server/log.php plugin before the patch associated with commit c3edcc274c389816d434acadac07ee78eaf330c1. Any user logged into such a system the application.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity risk. EPSS information is not available, and the vulnerability is not listed in CISA KEV, so current exploit probability data a legitimate user session and a simple POST request to log.php, making the attack path straightforward for potential impact of unauthorized wallet credit accumulation makes this a serious threat that can erode trust and revenue streams.

Generated by OpenCVE AI on September 11, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest WWBN AVideo patch that enforces proper ad impression authorization in AD_Server/log.php.
  • Restrict the AD_Server/log.php endpoint to only allow properly authenticated and authorized users, or disable the endpoint if it is not required for production.
  • Audit wallet credit transactions for abnormal activity and establish monitoring to detect rapid or large credit inflations.
  • Consider revoking or rotating credentials for any accounts that have historically performed frequent ad log submissions.

Generated by OpenCVE AI on September 11, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.
Title AVideo Missing Authorization via AD_Server log.php Wallet Credit
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-345
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T18:22:41.339Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:55.223

Modified: 2026-09-11T19:17:47.450

Link: CVE-2026-89251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:00:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity