CRITICAL🇵🇱 Wersja polska

CVE-2026-33867

CVSS 9.1v4.0pub. 2026-03-27upd. 2026-03-31

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the database (via SQL injection, a database backup, or misconfigured access controls), they obtain all video passwords in cleartext. Commit f2d68d2adbf73588ea61be2b781d93120a819e36 contains a patch.

🤖 AI Analysis
How it works

Content owners can password-protect individual videos on the AVideo platform. The platform stores these passwords directly in the database as plaintext (CWE-312 — storage of sensitive data without encryption). An attacker who gains read access to the database — via SQL injection, backup leak, or misconfigured permissions — receives all video passwords in readable form without the need to crack them.

Impact

An attacker can gain unauthorized access to all password-protected videos by bypassing the access control mechanism. Exposed passwords can also be used in attacks on other resources if users apply the same passwords elsewhere.

Mitigation & patch

Apply the patch contained in commit f2d68d2adbf73588ea61be2b781d93120a819e36 available in the WWBN/AVideo GitHub repository. It is also recommended to enforce a password change for all video passwords after the update that may have been previously exposed.

Who is affected

WWBN AVideo in versions up to 26.0 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Wwbn Avideo

    APP
    Wwbn
    ≤ 26.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-41064CRITICAL9.3PL ✓same product

WWBN AVideo — niekompletna naprawa command injection w test.php

CVE-2026-40911CRITICAL10.0PL ✓same product

WWBN AVideo: RCE przez eval() w pluginie YPTSocket — przejęcie kont

CVE-2026-34374CRITICAL9.1PL ✓same product

SQL Injection w WWBN AVideo — mechanizm uwierzytelniania RTMP

CVE-2026-33351CRITICAL9.1PL ✓same product

SSRF w WWBN AVideo — brak walidacji parametru URL w saveDVR.json.php

CVE-2026-33478CRITICAL10.0PL ✓same product

RCE bez uwierzytelnienia w WWBN AVideo — łańcuch podatności w pluginie CloneSite