Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35448

Опубликовано: 06 апр. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX polling helper for the authenticated invoice.php page, but it performs no access control checks of its own. Since Bitcoin addresses are publicly visible on the blockchain, an attacker can query payment records for any address used on the platform.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Версия до 26.0 (включая)

EPSS

Процентиль: 24%
0.00318
Низкий

3.7 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.7
github
5 месяцев назад

AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php

EPSS

Процентиль: 24%
0.00318
Низкий

3.7 Low

CVSS3

Дефекты

CWE-862