PT-2026-51173 · Avideo · Avideo
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 26.1
Description
Multiple payment plugins contain unauthenticated 'list.json.php' endpoints that lack proper authorization checks. This allows unauthenticated attackers to perform direct GET requests to these endpoints to retrieve sensitive payment transaction data, including PayPal tokens, Authorize.Net webhooks, Bitcoin transaction records, agreement IDs, user financial records, and API responses.
Recommendations
Update to a version later than 26.0.
As a temporary mitigation, restrict access to the 'list.json.php' endpoints within payment plugins.
Exploit
Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avideo