PT-2026-25998 · Wwbn · Avideo

Offensiveee

·

Published

2026-03-17

·

Updated

2026-03-20

·

CVE-2026-33041

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WWBN AVideo versions 25.0 and below
Description The /objects/encryptPass.json.php endpoint in WWBN AVideo exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receive their hashed equivalents, enabling offline password cracking against leaked database hashes. The encryptPassword() function uses a weak hash chain (md5+whirlpool+sha1, no salt by default), making password cracking extremely fast with access to database hashes. The vulnerable file is objects/encryptPass.json.php, and the vulnerable function is encryptPassword(). The encryptPassword() function is located in objects/functions.php around line 2101. The vulnerable parameter is pass in the API endpoint /objects/encryptPass.json.php.
Recommendations Versions 25.0 and below should be updated to version 26.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33041
GHSA-PX7X-GQ96-RMP5

Affected Products

Avideo