
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33485 is an unauthenticated time-based blind SQL injection vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The flaw resides in the RTMP on_publish callback endpoint (plugin/Live/on_publish.php), which is accessible without authentication and passes the $_POST['name'] (stream key) parameter directly into SQL queries without parameterized binding. It was published on March 20, 2026 via GitHub Advisory GHSA-8p58-35c3-ccxx and assigned a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is CWE-89 (SQL Injection): the $_POST['name'] parameter undergoes only superficial sanitization (stripping & and = characters via preg_replace) before being interpolated directly into SQL queries in two functions — LiveTransmitionHistory::getLatest() (unconditional, triggered on every request) and LiveTransmition::keyExists() (triggered when $_GET['p'] is provided). The sqlDAL::readSql() wrapper provides no protection when called without format/values parameters, as it passes the already-injected SQL string directly to mysqli->prepare() with no placeholders. An attacker needs only to send a POST request with tcurl and name parameters to the unauthenticated endpoint — no credentials, IP allowlisting, or session are required. A secondary logic flaw compounds the impact: on_publish.php:153 compares $_GET['p'] === $user->getPassword() against the raw stored bcrypt hash, meaning extracted hashes can be used directly to authenticate as any user (GitHub Advisory, AVideo Security Advisory).
An unauthenticated remote attacker can exfiltrate the entire database contents, including bcrypt password hashes, email addresses, personal information, API keys, session tokens, live stream passwords, and site configuration secrets. Because extracted password hashes can be passed directly as the $_GET['p'] parameter to authenticate as any user, attackers can impersonate arbitrary users and hijack live streams. Additionally, the vulnerability enables full database structure enumeration via information_schema queries, facilitating further exploitation of the platform and its users (GitHub Advisory).
A public proof-of-concept exploit consisting of step-by-step curl commands is included in the official security advisory and requires no compilation or special tooling (AVideo Security Advisory). The first injection point is reached unconditionally on every request, requiring only the name and tcurl POST parameters. The EPSS score is approximately 0.21–0.27%, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of reporting (GitHub Advisory).
/plugin/Live/on_publish.php endpoint.curl -s -o /dev/null -w "%{time_total}" \
-X POST "http://TARGET/plugin/Live/on_publish.php" \
-d "tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5)) %23"A ~5-second response confirms the injection is active.
3. Extract data character-by-character: Use conditional SLEEP() payloads to extract database contents, e.g., the first character of the admin password hash:
curl -s -o /dev/null -w "%{time_total}" \
-X POST "http://TARGET/plugin/Live/on_publish.php" \
-d "tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5) FROM users WHERE id=1 AND SUBSTRING(password,1,1)='\$') %23"information_schema tables via the same injection point to map all tables and columns for further data extraction.$_GET['p'] parameter in a subsequent request to on_publish.php, exploiting the flawed hash comparison at line 153 to impersonate any user and start streams on their behalf./plugin/Live/on_publish.php with name parameter values containing SQL keywords (SLEEP, SELECT, OR, SUBSTRING, information_schema) or URL-encoded comment characters (%23); abnormally slow HTTP response times (≥5 seconds) to this endpoint suggesting time-based injection probing./plugin/Live/on_publish.php from a single IP or rotating IPs with varying name parameter values; requests lacking valid RTMP stream context (e.g., tcurl=rtmp://localhost/live with no legitimate stream key).SLEEP(), SUBSTRING(), or information_schema references originating from the live_transmitions or live_transmition_history query context.$_GET['p'] values that match bcrypt hash patterns ($2y$...) rather than plaintext passwords, indicating use of extracted hashes for impersonation (AVideo Security Advisory).Apply the patch commit af59eade82de645b20183cc3d74467a7eac76549 from the WWBN/AVideo GitHub repository, which implements parameterized queries in LiveTransmition::keyExists(), LiveTransmitionHistory::getLatest(), and LiveTransmitionHistory::getLatestFromKey() using the existing sqlDAL::readSql() binding support (AVideo Patch Commit). As an interim workaround, restrict network access to /plugin/Live/on_publish.php via web server configuration (e.g., IP allowlist to trusted RTMP server IPs only). After patching, assume full database compromise: rotate all user passwords, API keys, session tokens, and live stream passwords, and audit for unauthorized stream activity (AVideo Security Advisory).
The vulnerability was reported by a researcher credited as "offset" in the GitHub security advisory and published by the AVideo maintainer DanielnetoDotCom on March 20, 2026 (AVideo Security Advisory). Social media activity was observed on Mastodon and Bluesky shortly after disclosure, with automated CVE tracking accounts amplifying the advisory. A technical write-up was published at infinitsec.net covering the unauthenticated blind SQL injection details (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."