GHSA-2f9f-v5qc-xhg6HighCVSS 6.5

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions...

Published
September 11, 2026
Last Modified
September 11, 2026

🔗 CVE IDs covered (1)

📋 Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.

🔗 References (4)