#VU125464 Session Fixation in AVideo - CVE-2026-33492
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to hijack an authenticated session.
The vulnerability exists due to session fixation in _session_start() and User::login() when processing a crafted same-domain link containing the PHPSESSID GET parameter. A remote user can send a specially crafted link to hijack an authenticated session.
User interaction is required, and exploitation relies on the victim following the link from within the AVideo platform so the request is treated as same-domain.