Medium severity6.5NVD Advisory· Published Sep 11, 2026
CVE-2026-89251
CVE-2026-89251
Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.
Affected products
3Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.