A AegiFlow
HIGHCVSS 8.7

GHSA-rg7q-4223-phjw

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Published
2026-06-20
Modified
2026-09-09
Sources
github-advisory

Summary

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wprj-9cvc-5w37. This link is maintained to preserve external references. ### Original Description AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user financial records, and API responses via direct GET requests to vulnerable endpoints.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistwwbn/avideo

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.