CVE-2026-33770: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33770 is a SQL Injection vulnerability in WWBN AVideo's category.php file, specifically within the fixCleanTitle() static method, which constructs SQL queries by directly interpolating user-supplied values without parameterization. It affects AVideo versions up to and including 26.0. The vulnerability was published on March 24, 2026, and added to the GitHub Advisory Database on March 26, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerable fixCleanTitle() method in objects/category.php directly interpolates both $clean_title (a user-supplied category name after slug conversion) and $id (the category ID) into a raw SQL string: SELECT * FROM categories WHERE clean_name = '{$clean_title}' with an optional AND id != {$id} clause — neither value is escaped or parameterized (GitHub Advisory). The slug conversion process strips spaces and some special characters but leaves SQL metacharacters (e.g., single quotes) intact, allowing UNION-based injection payloads to survive into the query. Exploitation requires triggering category creation or renaming with a crafted title, which is nominally an admin-level action, though lower-privilege paths may exist depending on plugin configuration. A proof-of-concept payload is publicly documented in the security advisory (AVideo Advisory).

Impact

Successful exploitation enables full database read access via UNION-based SQL injection, exposing user credentials (usernames and password hashes), private video metadata, and user personally identifiable information (PII). An attacker who exfiltrates database credentials could potentially escalate access to the underlying database server or pivot to other systems sharing those credentials. The confidentiality impact is high, while integrity and availability of the vulnerable system are not directly affected by this specific injection vector (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, providing a concrete UNION injection payload and step-by-step reproduction instructions (AVideo Advisory). Feedly classifies the exploit confidence as high and notes it is a real exploit targeting external AVideo deployments. There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.047%, indicating a low but non-negligible probability of exploitation in the near term (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances running version 26.0 or earlier using search engines (e.g., Shodan, Censys) or by checking the AVideo version disclosure on the platform's web interface.
  2. Obtain admin credentials: Authenticate to the AVideo admin panel using valid administrator credentials (obtained through phishing, credential stuffing, or other means), as category management requires admin-level access by default.
  3. Navigate to category management: Access the category creation or editing interface within the AVideo admin dashboard.
  4. Craft the malicious payload: Enter the following as the category title: test' UNION SELECT username,password,3,4,5,6,7,8,9,10 FROM users-- -
  5. Submit the form: Save or rename the category, triggering the fixCleanTitle() method in objects/category.php to process the input.
  6. Observe injected query execution: The backend executes: SELECT * FROM categories WHERE clean_name = 'test' UNION SELECT username,password,3,4,5,6,7,8,9,10 FROM users-- -' LIMIT 1, returning rows from the users table.
  7. Exfiltrate data: Retrieve the returned usernames and password hashes from the application response, enabling full credential exfiltration and further access (AVideo Advisory).

Indicators of compromise

  • Logs: Web server or application logs showing category save/rename requests containing SQL metacharacters such as single quotes ('), UNION SELECT, --, or FROM users in category title parameters.
  • Database: Unexpected or anomalous SQL queries in database query logs matching patterns like UNION SELECT username,password or queries referencing the users table from the category management context.
  • Application: Unusual category names in the AVideo database containing SQL fragments or appearing malformed after slug conversion.
  • Network: HTTP POST requests to AVideo category management endpoints (e.g., /objects/category.php or related admin save endpoints) with encoded or raw SQL injection strings in the body (AVideo Advisory).

Mitigation and workarounds

The fix is available in commit 994cc2b3d802b819e07e6088338e8bf4e484aae4, which refactors fixCleanTitle() to use prepared statements with ? placeholders and bound parameters ($clean_title as a string and intval($id) as an integer) (Patch Commit). Administrators should update AVideo to a version incorporating this commit (patched versions >= 26.0 per the advisory) immediately. As a temporary workaround, restrict access to the category management interface to trusted IP addresses via web server configuration, and deploy WAF rules to detect and block SQL injection patterns in request parameters (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher athuljayaram and published by AVideo maintainer DanielnetoDotCom on March 24, 2026, with a patch committed the same day (AVideo Advisory). The CVE received automated coverage from vulnerability aggregators including VulDB, CVEFeed, and CIRCL, but no notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE notification channels.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management