WWBN AVideo
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*
- <= 28.0
A vulnerability in WWBN AVideo versions prior to 29.0 allows for a signature verification bypass in the Authorize.Net webhook handler. This flaw enables attackers to forge webhook requests with arbitrary payment amounts and user IDs. By using a valid transaction ID from a small legitimate purchase, attackers can bypass signature validation and manipulate wallet balances on the platform. The vulnerability arises from three combined flaws: an OR logic signature bypass, payload values overriding API-fetched data, and a lack of approval checks before processing payments.
Exploitation of this vulnerability leads to unauthorized inflation of user wallet balances, allowing for fraudulent access to paid and premium content. Additionally, attackers can activate premium subscriptions without payment, causing direct financial loss to the platform owner.
To reproduce this vulnerability, an attacker must have a low-privileged account on an affected AVideo instance and have made a small purchase via Authorize.Net. After the purchase, the attacker can send a forged webhook request to the webhook.php endpoint, including a valid transaction ID, a high payment amount, and a metadata field specifying the target user ID. The webhook will be processed as if it were legitimate, crediting the specified amount to the user's wallet.
Users are advised to update to AVideo version 29.0, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.