
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33502 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open-source video platform. The flaw exists in the plugin/Live/test.php endpoint and affects all versions up to and including 26.0. It was disclosed on March 20, 2026, via a GitHub Security Advisory, with NVD publication on March 23, 2026. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) per Feedly/NVD, though the GitHub advisory assigns a score of 9.3 (Critical) with a scope-changed vector (GitHub Advisory).
The root cause is CWE-918 (Server-Side Request Forgery): the plugin/Live/test.php endpoint accepts a user-supplied statsURL parameter via $_REQUEST['statsURL'] and performs only a minimal check — verifying the value is non-empty, not php://input, and starts with http — before passing it directly to url_get_contents(), which internally calls file_get_contents() when allow_url_fopen is enabled. There is no authentication check, no allowlist of trusted URLs, no SSRF-safe validation (e.g., blocking RFC1918, loopback, or cloud metadata ranges), and the raw upstream response or error output is reflected back to the caller. Additionally, the file contains a wget fallback (lines 94–119) that constructs a shell command with the unsanitized URL, introducing potential shell injection risk. No preconditions are required — the endpoint is publicly accessible without authentication (GitHub Advisory).
An unauthenticated remote attacker can leverage this vulnerability to probe localhost and internal network services, enumerate open and closed ports by observing connection-refused versus successful responses, access cloud instance metadata endpoints (e.g., http://169.254.169.254/) if reachable from the server, and retrieve the full body of internal HTTP responses. The primary impact is high confidentiality loss — sensitive internal service data, credentials, or cloud metadata may be exfiltrated — with a low integrity impact due to the ability to interact with internal services. No direct unauthenticated code execution was validated from this specific issue in the tested environment, though it can serve as a stepping stone for further attacks (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete curl commands that demonstrate port probing and internal service interaction against a live AVideo deployment. The EPSS score is approximately 0.041% (0.000410), indicating a currently low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation at this time, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog. Qualys has added detection for this CVE (detection ID 5009456) (GitHub Advisory).
/plugin/Live/test.php.curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:80/'. A response containing server-side output (e.g., upstream HTTP headers or content) confirms the endpoint is live and vulnerable.curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:1/'. A Connection refused error in the response indicates a closed port; a successful response body indicates an open service.curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://127.0.0.1:9200/'.curl -s 'http://<TARGET>/plugin/Live/test.php?statsURL=http://169.254.169.254/latest/meta-data/'. A successful response may yield IAM credentials, instance identity, or other sensitive cloud configuration data (GitHub Advisory)./plugin/Live/test.php with a statsURL parameter containing internal IP addresses, loopback addresses, or metadata endpoints; PHP error log entries containing file_get_contents failure messages referencing internal hosts (e.g., Failed to open stream: Connection refused for http://127.0.0.1:<port>/)._log entries) showing file_get_contents:: output with internal service responses or error messages reflected from internal hosts.wget child processes spawned by the PHP/web server process with URLs pointing to internal network resources (GitHub Advisory).The recommended remediation is to update AVideo to version 26.1 or later, which includes the patch in commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3. If immediate upgrade is not possible, the safest workaround is to remove plugin/Live/test.php from production deployments entirely, or block public access to it via web server configuration (Apache/Nginx deny rules). If the file must remain, add admin authentication (User::isAdmin() check), restrict statsURL to an explicit allowlist of trusted Live stats URLs, block requests to localhost/RFC1918/link-local/metadata IP ranges using an isSSRFSafeURL() function (already available in objects/functions.php), stop reflecting fetched bodies and raw upstream errors to the client, and remove or sanitize the wget fallback using escapeshellarg(). Additionally, implement network-level egress filtering to block the web server process from reaching internal RFC1918 and metadata addresses (GitHub Advisory).
The vulnerability received coverage from security news outlets including The Hacker Wire and SecurityOnline.info, the latter covering multiple critical AVideo vulnerabilities disclosed simultaneously. Social media discussion was noted on Mastodon and Bluesky, with automated CVE tracking accounts amplifying the advisory. The yazoul.net security blog published a dedicated advisory writeup. Overall community sentiment treated this as a moderate-to-high severity finding given the zero-authentication requirement, though the absence of direct code execution limited alarm compared to the co-disclosed CSRF/RCE issue (CVE-2026-33507) (The Hacker Wire, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."