Back

CRITICAL

WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php

Published Mar 6, 2026

Description

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is supplied via a JSON-formatted POST request body. Because JSON input is parsed and merged into $_REQUEST after global security checks are executed, the payload bypasses the existing sanitization mechanisms. This issue has been patched in version 24.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 6, 2026
Updated Mar 6, 2026
Reserved Feb 27, 2026
CISA Vulnrichment
Updated Mar 6, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 6, 2026
Updated Mar 6, 2026
Exploited since n/a
EUVD-2026-9970 GHSA-PV87-R9QF-X56P