#VU125443 Information disclosure in AVideo - CVE-2026-33043
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to hijack a user's session and take over the account.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in /objects/phpsessionid.json.php when handling credentialed cross-origin requests. A remote attacker can host a crafted webpage that triggers a cross-origin request and reads the returned session ID to hijack a user's session and take over the account.
User interaction is required, and exploitation occurs when a logged-in user visits an attacker-controlled page.