Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-33731— AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

Quick assessment

Affected
WWBN AVideo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0之前版本存在输入验证错误漏洞,该漏洞源于Authorize.Net webhook处理程序中签名验证绕过,允许攻击者伪造webhook请求,通过OR逻辑绕过签名验证、有效载荷值覆盖API获取值以及缺少审批检查,从而向任意用户钱包充值任意金额并激活高级订阅,导致直接收入损失。

CVSS 6.5 · Medium EPSS 0.21% · P11

Affected Version Matrix 1

VendorProduct Version RangeStatus
WWBN AVideo < 29.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-33731

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data
Source: CVE Program / CVE List V5
Vulnerability Description
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary payment amounts and target user IDs. By supplying a valid transaction ID from a small legitimate purchase, the attacker bypasses signature validation and credits arbitrary wallet balances to any user account via attacker-controlled payload fields. Three flaws combine into an exploit chain: signature bypass via OR logic (webhook.php:33), payload values override API-fetched values (AuthorizeNet.php:169-171, webhook.php:44-48) and a missing approval check (webhook.php:61-75). By forging payment metadata, an attacker can credit arbitrary amounts to any user's wallet without a corresponding payment and include a  plans_id  to activate premium subscriptions (webhook.php:86-134), enabling free access to all paid and premium content and causing direct revenue loss to the platform owner. This issue has been fixed in version 29.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5
Vulnerability Title
WWBN AVideo 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WWBN avideo是WWBN组织开源的一套视频内容管理系统。 WWBN AVideo 29.0之前版本存在输入验证错误漏洞,该漏洞源于Authorize.Net webhook处理程序中签名验证绕过,允许攻击者伪造webhook请求,通过OR逻辑绕过签名验证、有效载荷值覆盖API获取值以及缺少审批检查,从而向任意用户钱包充值任意金额并激活高级订阅,导致直接收入损失。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
WWBN AVideo < 29.0 -

II. Public POCs for CVE-2026-33731

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-33731

登录查看更多情报信息。

Patches & Fixes for CVE-2026-33731 (1)

Vendor Advisories for CVE-2026-33731 (1)

Same Patch Batch · WWBN · 2026-07-16 · 5 CVEs total

CVE-2026-55173 8.1 HIGH AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&'
CVE-2026-63305 8.1 HIGH AVideo through 29.0 OS Command Injection via ffmpeg.json.php
CVE-2026-63304 8.1 HIGH AVideo through 29.0 OS Command Injection via listFFmpegProcesses
CVE-2026-33692 7.5 HIGH AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration

IV. Related Vulnerabilities

V. Comments for CVE-2026-33731

No comments yet


Leave a comment