PT-2026-27184 · Avideo · Avideo
Restriction
·
Publicado
2026-03-23
·
Atualizado
2026-03-25
·
CVE-2026-33651
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions up to and including 26.0
Description
AVideo is an open source video platform. The
remindMe.json.php endpoint passes the $ REQUEST['live schedule id'] variable through multiple functions without proper sanitization. This ultimately leads to direct concatenation of the variable into a SQL LIKE clause within the Scheduler commands::getAllActiveOrToRepeat() function. While some intermediate functions apply intval() to local copies of the variable, the original tainted variable remains unchanged. This allows an authenticated user to perform time-based blind SQL injection to extract arbitrary database contents.Recommendations
Update AVideo to a version newer than 26.0.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Avideo