{"id":"CVE-2026-33485","aliases":["GHSA-8p58-35c3-ccxx"],"url":"https://o3.security/vulnerability/CVE-2026-33485","summary":"AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter","details":"WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated directly into SQL queries in two locations — `LiveTransmitionHistory::getLatest()` and `LiveTransmition::keyExists()` — without parameterized binding or escaping. An unauthenticated attacker can exploit time-based blind SQL injection to extract all database contents including user password hashes, email addresses, and other sensitive data. Commit af59eade82de645b20183cc3d74467a7eac76549 contains a patch.","published":"2026-03-23T14:14:15.477Z","modified":"2026-08-12T03:51:22.001205112Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"wwbn/avideo","fixedVersion":null}],"fix":{"url":"https://github.com/WWBN/AVideo/commit/af59eade82de645b20183cc3d74467a7eac76549","label":"WWBN/AVideo@af59ead"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33485.json"},{"type":"ADVISORY","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-8p58-35c3-ccxx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33485"},{"type":"FIX","url":"https://github.com/WWBN/AVideo/commit/af59eade82de645b20183cc3d74467a7eac76549"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.001205112Z"}}