CVE-2026-33485: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33485 is an unauthenticated time-based blind SQL injection vulnerability in WWBN AVideo affecting all versions up to and including 26.0. The flaw resides in the RTMP on_publish callback endpoint (plugin/Live/on_publish.php), which is accessible without authentication and passes the $_POST['name'] (stream key) parameter directly into SQL queries without parameterized binding. It was published on March 20, 2026 via GitHub Advisory GHSA-8p58-35c3-ccxx and assigned a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is CWE-89 (SQL Injection): the $_POST['name'] parameter undergoes only superficial sanitization (stripping & and = characters via preg_replace) before being interpolated directly into SQL queries in two functions — LiveTransmitionHistory::getLatest() (unconditional, triggered on every request) and LiveTransmition::keyExists() (triggered when $_GET['p'] is provided). The sqlDAL::readSql() wrapper provides no protection when called without format/values parameters, as it passes the already-injected SQL string directly to mysqli->prepare() with no placeholders. An attacker needs only to send a POST request with tcurl and name parameters to the unauthenticated endpoint — no credentials, IP allowlisting, or session are required. A secondary logic flaw compounds the impact: on_publish.php:153 compares $_GET['p'] === $user->getPassword() against the raw stored bcrypt hash, meaning extracted hashes can be used directly to authenticate as any user (GitHub Advisory, AVideo Security Advisory).

Impact

An unauthenticated remote attacker can exfiltrate the entire database contents, including bcrypt password hashes, email addresses, personal information, API keys, session tokens, live stream passwords, and site configuration secrets. Because extracted password hashes can be passed directly as the $_GET['p'] parameter to authenticate as any user, attackers can impersonate arbitrary users and hijack live streams. Additionally, the vulnerability enables full database structure enumeration via information_schema queries, facilitating further exploitation of the platform and its users (GitHub Advisory).

Exploitability

A public proof-of-concept exploit consisting of step-by-step curl commands is included in the official security advisory and requires no compilation or special tooling (AVideo Security Advisory). The first injection point is reached unconditionally on every request, requiring only the name and tcurl POST parameters. The EPSS score is approximately 0.21–0.27%, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of reporting (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions ≤ 26.0) using search engines like Shodan or Censys, looking for the /plugin/Live/on_publish.php endpoint.
  2. Confirm injection: Send a time-based blind SQL injection probe to verify vulnerability:
curl -s -o /dev/null -w "%{time_total}" \
  -X POST "http://TARGET/plugin/Live/on_publish.php" \
  -d "tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5)) %23"

A ~5-second response confirms the injection is active. 3. Extract data character-by-character: Use conditional SLEEP() payloads to extract database contents, e.g., the first character of the admin password hash:

curl -s -o /dev/null -w "%{time_total}" \
  -X POST "http://TARGET/plugin/Live/on_publish.php" \
  -d "tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5) FROM users WHERE id=1 AND SUBSTRING(password,1,1)='\$') %23"
  1. Enumerate database structure: Query information_schema tables via the same injection point to map all tables and columns for further data extraction.
  2. Authenticate as any user: Use the extracted bcrypt hash directly as the $_GET['p'] parameter in a subsequent request to on_publish.php, exploiting the flawed hash comparison at line 153 to impersonate any user and start streams on their behalf.
  3. Pivot: Use extracted API keys, session tokens, and credentials to access additional platform functionality or connected services (AVideo Security Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /plugin/Live/on_publish.php with name parameter values containing SQL keywords (SLEEP, SELECT, OR, SUBSTRING, information_schema) or URL-encoded comment characters (%23); abnormally slow HTTP response times (≥5 seconds) to this endpoint suggesting time-based injection probing.
  • Logs: Web server access logs showing repeated POST requests to /plugin/Live/on_publish.php from a single IP or rotating IPs with varying name parameter values; requests lacking valid RTMP stream context (e.g., tcurl=rtmp://localhost/live with no legitimate stream key).
  • Application: Database query logs (if enabled) showing SQL queries with injected SLEEP(), SUBSTRING(), or information_schema references originating from the live_transmitions or live_transmition_history query context.
  • Authentication: Unexpected stream authentication attempts using $_GET['p'] values that match bcrypt hash patterns ($2y$...) rather than plaintext passwords, indicating use of extracted hashes for impersonation (AVideo Security Advisory).

Mitigation and workarounds

Apply the patch commit af59eade82de645b20183cc3d74467a7eac76549 from the WWBN/AVideo GitHub repository, which implements parameterized queries in LiveTransmition::keyExists(), LiveTransmitionHistory::getLatest(), and LiveTransmitionHistory::getLatestFromKey() using the existing sqlDAL::readSql() binding support (AVideo Patch Commit). As an interim workaround, restrict network access to /plugin/Live/on_publish.php via web server configuration (e.g., IP allowlist to trusted RTMP server IPs only). After patching, assume full database compromise: rotate all user passwords, API keys, session tokens, and live stream passwords, and audit for unauthorized stream activity (AVideo Security Advisory).

Community reactions

The vulnerability was reported by a researcher credited as "offset" in the GitHub security advisory and published by the AVideo maintainer DanielnetoDotCom on March 20, 2026 (AVideo Security Advisory). Social media activity was observed on Mastodon and Bluesky shortly after disclosure, with automated CVE tracking accounts amplifying the advisory. A technical write-up was published at infinitsec.net covering the unauthenticated blind SQL injection details (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management