CVE-2026-33499: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33499 is a reflected Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, affecting all versions up to and including 26.0. The flaw exists in view/forbiddenPage.php and view/warningPage.php, where the unlockPassword request parameter is reflected directly into HTML attributes without output encoding or sanitization. It was disclosed on March 20, 2026, via a GitHub Security Advisory, and published to the NVD on March 23, 2026. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), classified as reflected XSS. When a user visits a password-protected channel and the supplied password is incorrect or absent, view/channel.php calls forbiddenPage(), which includes view/forbiddenPage.php. At line 33, the raw $_REQUEST['unlockPassword'] value is assigned without sanitization and passed to getInputPassword(), which outputs it directly into an HTML <input> tag's attribute string. The unlockPassword parameter is absent from all global security filter arrays in objects/security.php, so it bypasses the application's existing input sanitization entirely. A prior commit (3933d4abc) added server-side sanitization for password comparison only, leaving the client-side reflection unaddressed. The identical flaw exists in view/warningPage.php (GitHub Advisory, AVideo Security Advisory).

Impact

Successful exploitation enables session hijacking by stealing PHPSESSID cookies, allowing an attacker to impersonate any user — including administrators — who clicks a crafted link. The injected JavaScript executes in the context of the target domain with access to cookies, the DOM, and the ability to make authenticated requests on behalf of the victim, enabling account takeover by modifying email addresses and passwords via account settings endpoints. Additionally, attackers can overlay fake login forms or redirect victims to credential harvesting pages. The vulnerable pages are shown to unauthenticated users, broadening the attack surface significantly (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, providing a concrete crafted URL payload and step-by-step reproduction instructions (AVideo Security Advisory). No authentication is required to exploit this vulnerability. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.01% (0.0001), placing it in the 6th percentile for exploitation probability within 30 days (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify AVideo instances running version 26.0 or earlier using search engines (e.g., Shodan, Censys) or by browsing to the target and checking version indicators. Locate a password-protected channel or any page that triggers forbiddenPage() or warningPage().
  2. Craft malicious URL: Construct a URL targeting the vulnerable channel with a malicious unlockPassword parameter that breaks out of the HTML value attribute and injects a JavaScript event handler:
    https://target.com/channel/someuser?unlockPassword=" autofocus onfocus="alert(document.cookie)
  3. Deliver the payload: Send the crafted URL to the victim via phishing email, social media message, or any other social engineering channel. The target page is shown to unauthenticated users, so no prior session is needed.
  4. Trigger execution: When the victim clicks the link, the server renders the unsanitized parameter into the <input> tag. The autofocus attribute causes the browser to immediately focus the element, triggering the onfocus event handler and executing the attacker's JavaScript without any additional user interaction.
  5. Achieve objective: Replace alert(document.cookie) with a payload that exfiltrates the PHPSESSID cookie to an attacker-controlled server, submits forms to account settings endpoints to change credentials, or overlays a fake login form for credential harvesting (AVideo Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to attacker-controlled domains carrying PHPSESSID cookie values in query parameters or POST bodies; unusual requests to AVideo account settings endpoints (e.g., password/email change) originating from unexpected IP addresses or sessions.
  • Logs: Web server access logs showing requests to /channel/ or pages triggering forbiddenPage.php/warningPage.php with unlockPassword parameter values containing HTML special characters such as ", autofocus, onfocus, <script>, or URL-encoded equivalents.
  • File System: No direct file system artifacts expected for reflected XSS; however, monitor for new or modified PHP files in the AVideo installation directory that could indicate follow-on compromise after session hijacking.
  • Process/Application: Unexpected account credential changes (email or password modifications) in AVideo user records, particularly for administrator accounts, without corresponding legitimate user activity (AVideo Security Advisory).

Mitigation and workarounds

The fix was committed in AVideo commit f154167251c9cf183ce09cd018d07e9352310457, which applies htmlspecialchars() output encoding to the reflected unlockPassword value in both view/forbiddenPage.php and view/warningPage.php (AVideo Patch Commit). Administrators should update AVideo to a version incorporating this commit immediately. As interim mitigations, implement a Content Security Policy (CSP) header to restrict inline script execution, enable HttpOnly and Secure flags on session cookies to prevent JavaScript access, and add unlockPassword to the $securityFilter array in objects/security.php as a defense-in-depth measure (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management