CVE-2026-33492
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's _session_start() function accepts arbitrary session IDs via the PHPSESSID GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific blacklisted endpoints when the request originates from the same domain.
Combined with the explicitly disabled session regeneration in User::login(), this allows a classic session fixation attack where an attacker can fix a victim's session ID before authentication and then hijack the authenticated session. Commit 5647a94d79bf69a972a86653fe02144079948785 contains a patch.
HIGH · CVSS 7.3
EPSS 0.00099
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0