#VU125507 Missing Authorization in AVideo - CVE-2026-35448
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive payment order information.
The vulnerability exists due to missing authorization in the BlockonomicsYPT check.php endpoint when handling requests for a supplied Bitcoin address. A remote attacker can send a specially crafted request with a known Bitcoin address to disclose sensitive payment order information.
Bitcoin addresses used by the platform may be discoverable from public blockchain data, and no session cookie or API key is required.