PT-2026-27184 · Avideo · Avideo

Restriction

·

Published

2026-03-23

·

Updated

2026-03-25

·

CVE-2026-33651

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The remindMe.json.php endpoint passes the $ REQUEST['live schedule id'] variable through multiple functions without proper sanitization. This ultimately leads to direct concatenation of the variable into a SQL LIKE clause within the Scheduler commands::getAllActiveOrToRepeat() function. While some intermediate functions apply intval() to local copies of the variable, the original tainted variable remains unchanged. This allows an authenticated user to perform time-based blind SQL injection to extract arbitrary database contents.
Recommendations Update AVideo to a version newer than 26.0.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-33651
GHSA-PVW4-P2JM-CHJM

Affected Products

Avideo