CVE-2026-33043

Published
View on NVD ↗
CVSS v3
8.1
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true, enabling cross-origin session theft and full account takeover. This issue has been fixed in version 26.0.

Create Your Own Broadcast Network With AVideo Platform Open-Source. OAVP OVP
GitHubGitHub
2.1K