PT-2026-28624 · Wwbn · Avideo

Adrgs

·

Publicado

2026-03-27

·

Atualizado

2026-03-28

·

CVE-2026-34374

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions up to and including 26.0
Description WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Live schedule::keyExists() method builds a SQL query by directly inserting a stream key into the query string without proper parameterization. This occurs as a fallback mechanism from LiveTransmition::keyExists() when the primary, parameterized lookup fails. This bypasses the security measures of the initial lookup. The issue targets the stream key lookup used during RTMP publish authentication. Attackers may be able to access the entire user database through live streams. The Live schedule::keyExists() function is vulnerable.
Recommendations Versions up to and including 26.0 should be updated when a patched version becomes available. As a temporary workaround, consider disabling the Live schedule::keyExists() function until a patch is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34374
GHSA-XGV5-66WP-CH88

Produtos afetados

Avideo