Description
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity (arbitrary vote manipulation)
Action: Apply Patch
AI Analysis

Impact

Like::__construct() performs counter arithmetic on raw request values before validation, permitting array-typed parameters to desynchronize stored votes from denormalized counters. Authenticated attackers can send an array-typed like parameter followed by normal requests, causing the video like count to decrease arbitrarily, including negative values. This corrupts the integrity of the like data and can persist until manual intervention, undermining trust in the platform.

Affected Systems

The vulnerability exists in the WWBN AVideo platform up through version 29.0. Any deployment of AVideo 29.0 or earlier is affected, regardless of configuration. Updates beyond 29.0 remove the flaw.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% signals a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated web user and relies on sending specially crafted array parameters; therefore, the attack vector is authenticated and application‑level. The impact is confined to the integrity of video vote counts but can affect user perception and platform credibility.

Generated by OpenCVE AI on September 17, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AVideo to version 29.1 or later, which removes the counter arithmetic on raw input.
  • If a patch is not available, block or validate array‑typed like parameters, ensuring only scalar values are processed.
  • Audit existing like data for negative counts and correct manually to restore accurate vote totals.

Generated by OpenCVE AI on September 17, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.
Title AVideo through 29.0 Like Counter Desynchronization via Array Parameter
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-20
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:49:51.086Z

Reserved: 2026-09-16T13:47:20.117Z

Link: CVE-2026-92581

cve-icon Vulnrichment

Updated: 2026-09-17T14:49:46.823Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:18:28.470

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-20

    Improper Input Validation