{"id":"GHSA-9392-pj54-qqf8","summary":"WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint","details":"### Summary\n\n  `plugin/AuthorizeNet/processPayment.json.php` credits the logged-in user's wallet based only on the attacker-controlled `amount` POST parameter.\n\n  The endpoint contains a TODO for real Authorize.Net charging, hardcodes `$paymentSuccess = true`, and then calls `YPTWallet::addBalance()` without validating\n  any Authorize.Net transaction, webhook signature, hosted payment token, nonce, or server-side payment record.\n\n  This allows any logged-in user to add arbitrary funds to their own AVideo wallet when the `AuthorizeNet` and `YPTWallet` plugins are enabled.\n\n  ### Details\n\n  Affected file:\n\n  `plugin/AuthorizeNet/processPayment.json.php`\n\n  Relevant code:\n\n  ```php\n  $amount = isset($_POST['amount']) ? floatval($_POST['amount']) : 0;\n  $userData = isset($_POST['userData']) ? $_POST['userData'] : [];\n\n  if ($amount \u003c= 0) {\n      echo json_encode(['error' =\u003e 'Invalid amount']);\n      exit;\n  }\n\n  // TODO: Implement payment logic using Authorize.Net API\n  // Example: Call Authorize.Net API here\n  // $result = $plugin-\u003echargePayment($amount, $userData);\n\n  // Simulate payment success for now\n  $paymentSuccess = true;\n  $users_id = @User::getId();\n\n  if ($paymentSuccess && !empty($users_id)) {\n      $walletPlugin = AVideoPlugin::loadPluginIfEnabled(\"YPTWallet\");\n      if ($walletPlugin) {\n          $walletPlugin-\u003eaddBalance($users_id, $amount, 'Authorize.Net one-time payment');\n          echo json_encode(['success' =\u003e true, 'result' =\u003e 'Payment processed and wallet updated']);\n          exit;\n      }\n  }\n```\n  Vulnerable flow:\n\n  1. `$_POST['amount']` is read from the client.\n  2. The endpoint only checks that the amount is greater than zero.\n  3. The real Authorize.Net charge is not performed.\n  4. `$paymentSuccess` is hardcoded to true.\n  5. The logged-in user's wallet is credited with the client-supplied amount.\n\n  There is no verification of:\n\n  - Authorize.Net transaction ID\n  - payment token\n  - webhook signature\n  - pending payment record\n  - expected server-side amount\n  - currency\n  - duplicate transaction/replay state\n\n  ### PoC\n\n  Prerequisites:\n\n  - AVideo with AuthorizeNet plugin enabled\n  - YPTWallet plugin enabled\n  - Attacker has any valid user account\n\n  Steps:\n\n  1. Log in as a low-privileged user.\n  2. Open the wallet page and record the current balance.\n  3. Send the following request with the user's authenticated session cookie:\n```\n  curl -i -s -b 'PHPSESSID=\u003cuser_session\u003e' \\\n    -X POST 'https://target.example/plugin/AuthorizeNet/processPayment.json.php' \\\n    --data 'amount=9999&userData[note]=poc'\n```\n  4. The endpoint returns:\n```\n  {\"success\":true,\"result\":\"Payment processed and wallet updated\"}\n```\n  5. Refresh the wallet page.\n  6. The wallet balance is increased by 9999.\n\n  No Authorize.Net hosted payment page, card payment, transaction confirmation, webhook, or server-side payment validation is required.\n\n### Impact\n\n  A normal authenticated user can mint arbitrary wallet balance.\n\n  Depending on the target site's configuration, this may allow the attacker to:\n\n  - purchase paid videos or subscriptions without payment\n  - abuse any feature backed by YPTWallet\n  - transfer fake funds to other users\n  - manipulate accounting or payout-related workflows\n  - bypass monetization controls\n\n### Recommended fix\n\n- Remove or disable `processPayment.json.php` if it is obsolete.\n- Never credit wallet balance from client-supplied `amount` alone.\n- Use the existing Authorize.Net hosted token / webhook / transaction reconciliation flow.\n- Require a verified Authorize.Net transaction ID and server-side amount lookup before calling `addBalance()`.\n- Add regression tests proving arbitrary POSTs cannot credit a wallet.","aliases":["CVE-2026-47696"],"modified":"2026-09-10T03:50:49.076765453Z","published":"2026-06-04T18:47:35Z","database_specific":{"cwe_ids":["CWE-345"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-04T18:47:35Z","nvd_published_at":"2026-05-29T14:16:32Z"},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-9392-pj54-qqf8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47696"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/822402444b4db4e9442779c8c789ffe5312b3627"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"WWBN/AVideo","ecosystem":"Packagist","purl":"pkg:composer/WWBN/AVideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"29.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9392-pj54-qqf8/GHSA-9392-pj54-qqf8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}