PT-2026-22880 · Avideo · Avideo
Daniel Neto
·
Published
2026-03-02
·
Updated
2026-04-17
·
CVE-2026-28501
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AVideo versions prior to 23
Description
The software contains an unauthenticated SQL injection flaw within the
objects/videos.json.php and objects/video.php components. The application does not properly sanitize the catName parameter when received in a JSON-formatted POST request, bypassing existing security checks. This allows an attacker to execute arbitrary SQL queries, potentially leading to database exfiltration, extraction of sensitive data like administrator usernames and password hashes, privilege escalation, and full system compromise. The issue is categorized as CWE-89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection).Recommendations
Upgrade to version 23 or later.
Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo