PT-2026-27184 · Avideo · Avideo

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-25

·

CVE-2026-33651

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The remindMe.json.php endpoint passes the $ REQUEST['live schedule id'] variable through multiple functions without proper sanitization. This ultimately leads to direct concatenation of the variable into a SQL LIKE clause within the Scheduler commands::getAllActiveOrToRepeat() function. While some intermediate functions apply intval() to local copies of the variable, the original tainted variable remains unchanged. This allows an authenticated user to perform time-based blind SQL injection to extract arbitrary database contents.
Recommendations Update AVideo to a version newer than 26.0.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33651
GHSA-PVW4-P2JM-CHJM

Produtos afetados

Avideo