
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33499 is a reflected Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, affecting all versions up to and including 26.0. The flaw exists in view/forbiddenPage.php and view/warningPage.php, where the unlockPassword request parameter is reflected directly into HTML attributes without output encoding or sanitization. It was disclosed on March 20, 2026, via a GitHub Security Advisory, and published to the NVD on March 23, 2026. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as reflected XSS. When a user visits a password-protected channel and the supplied password is incorrect or absent, view/channel.php calls forbiddenPage(), which includes view/forbiddenPage.php. At line 33, the raw $_REQUEST['unlockPassword'] value is assigned without sanitization and passed to getInputPassword(), which outputs it directly into an HTML <input> tag's attribute string. The unlockPassword parameter is absent from all global security filter arrays in objects/security.php, so it bypasses the application's existing input sanitization entirely. A prior commit (3933d4abc) added server-side sanitization for password comparison only, leaving the client-side reflection unaddressed. The identical flaw exists in view/warningPage.php (GitHub Advisory, AVideo Security Advisory).
Successful exploitation enables session hijacking by stealing PHPSESSID cookies, allowing an attacker to impersonate any user — including administrators — who clicks a crafted link. The injected JavaScript executes in the context of the target domain with access to cookies, the DOM, and the ability to make authenticated requests on behalf of the victim, enabling account takeover by modifying email addresses and passwords via account settings endpoints. Additionally, attackers can overlay fake login forms or redirect victims to credential harvesting pages. The vulnerable pages are shown to unauthenticated users, broadening the attack surface significantly (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, providing a concrete crafted URL payload and step-by-step reproduction instructions (AVideo Security Advisory). No authentication is required to exploit this vulnerability. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.01% (0.0001), placing it in the 6th percentile for exploitation probability within 30 days (GitHub Advisory).
forbiddenPage() or warningPage().unlockPassword parameter that breaks out of the HTML value attribute and injects a JavaScript event handler:https://target.com/channel/someuser?unlockPassword=" autofocus onfocus="alert(document.cookie)<input> tag. The autofocus attribute causes the browser to immediately focus the element, triggering the onfocus event handler and executing the attacker's JavaScript without any additional user interaction.alert(document.cookie) with a payload that exfiltrates the PHPSESSID cookie to an attacker-controlled server, submits forms to account settings endpoints to change credentials, or overlays a fake login form for credential harvesting (AVideo Security Advisory).PHPSESSID cookie values in query parameters or POST bodies; unusual requests to AVideo account settings endpoints (e.g., password/email change) originating from unexpected IP addresses or sessions./channel/ or pages triggering forbiddenPage.php/warningPage.php with unlockPassword parameter values containing HTML special characters such as ", autofocus, onfocus, <script>, or URL-encoded equivalents.The fix was committed in AVideo commit f154167251c9cf183ce09cd018d07e9352310457, which applies htmlspecialchars() output encoding to the reflected unlockPassword value in both view/forbiddenPage.php and view/warningPage.php (AVideo Patch Commit). Administrators should update AVideo to a version incorporating this commit immediately. As interim mitigations, implement a Content Security Policy (CSP) header to restrict inline script execution, enable HttpOnly and Secure flags on session cookies to prevent JavaScript access, and add unlockPassword to the $securityFilter array in objects/security.php as a defense-in-depth measure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."