← Retour à la recherche de CVE

CVE-2026-43883

WWBN AVideo

Description

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.json.php cancels a PayPal billing agreement using an attacker-supplied agreement parameter without verifying that the authenticated user owns the agreement. A low-privilege authenticated user who learns or obtains another user-s PayPal billing agreement ID can silently suspend the victim-s recurring subscription, causing revenue loss to the platform and loss of paid service to the victim. Commit 0da3dcff1eda2f497694bf82b559829471c292c2 contains an updated fix.

CVSS 4.2EPSS 0.167%Risque 0.43
Voir la source
Publication
2026-05-11 22:22:12
Versions concernées
<=29.0
Type
Core software
Vecteur
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L