| Summary | WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Authorize.Net charging, hardcodes $paymentSuccess = true, and then calls YPTWallet::addBalance() without validating |
|---|---|
| Publication Date | May 29, 2026, 11:16 p.m. |
| Registration Date | May 30, 2026, 4:14 a.m. |
| Last Update | May 30, 2026, 12:16 a.m. |