CyberRota Analysis
AI-GeneratedAVideo's failure to validate ad impressions in the AD_Server plugin allows authenticated users to exploit the system by submitting arbitrary label values, which can lead to unauthorized wallet credits for campaign video owners. This vulnerability enables attackers to manipulate ad metrics and potentially mint YPTWallet balances without legitimate ad views. Organizations using AVideo should prioritize addressing this issue to prevent financial exploitation and maintain the integrity of their advertising systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.