Impact
Like::__construct() performs counter arithmetic on raw request values before validation, permitting array-typed parameters to desynchronize stored votes from denormalized counters. Authenticated attackers can send an array-typed like parameter followed by normal requests, causing the video like count to decrease arbitrarily, including negative values. This corrupts the integrity of the like data and can persist until manual intervention, undermining trust in the platform.
Affected Systems
The vulnerability exists in the WWBN AVideo platform up through version 29.0. Any deployment of AVideo 29.0 or earlier is affected, regardless of configuration. Updates beyond 29.0 remove the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% signals a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated web user and relies on sending specially crafted array parameters; therefore, the attack vector is authenticated and application‑level. The impact is confined to the integrity of video vote counts but can affect user perception and platform credibility.
OpenCVE Enrichment