{"id":"GHSA-pv87-r9qf-x56p","summary":"AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php","details":"## Impact\n\nAn unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components.\n\nThe application fails to properly sanitize the catName parameter when it is supplied via a JSON-formatted POST request body. Because JSON input is parsed and merged into $_REQUEST after global security checks are executed, the payload bypasses the existing sanitization mechanisms.\n\nThis allows an unauthenticated attacker to:\n\n- Execute arbitrary SQL queries\n- Perform full database exfiltration\n- Extract sensitive data including administrator usernames, password hashes, session identifiers and user records\n- Potentially escalate privileges by cracking password hashes offline\n- Chain with authenticated vulnerabilities to achieve full system compromise\n\nThis vulnerability is classified as:\n- CWE-89: Improper Neutralization of Special Elements used in an SQL Command (SQL Injection)\n\n\n## Patches\n\nThis vulnerability has been fixed in version 23.\n\nUsers must upgrade to version 23 or later.\n\n\n## Workarounds\n\nThere is no reliable workaround.\n\nThe only recommended mitigation is to upgrade immediately to version 23 upon its release.\n\n\n## References\n\nInternal security report.","aliases":["CVE-2026-28501"],"modified":"2026-03-06T14:31:26.323078Z","published":"2026-03-02T20:49:43Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-03-02T20:49:43Z","nvd_published_at":"2026-03-06T04:16:08Z","cwe_ids":["CWE-89"]},"references":[{"type":"WEB","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-pv87-r9qf-x56p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28501"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/commit/0c10be681c64044618ab94473251bd7c9b114fa1"},{"type":"PACKAGE","url":"https://github.com/WWBN/AVideo"},{"type":"WEB","url":"https://github.com/WWBN/AVideo/releases/tag/24.0"}],"affected":[{"package":{"name":"wwbn/avideo","ecosystem":"Packagist","purl":"pkg:composer/wwbn/avideo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"21.0.0"}]}],"versions":["10.4","10.8","11","11.1","11.1.1","11.5","11.6","12.4","14.3","14.3.1","14.4","18.0","21.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-pv87-r9qf-x56p/GHSA-pv87-r9qf-x56p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}