Code Injection in AVideo - CVE-2026-33479
Published: May 4, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to code injection in saveSort.json.php through use of eval() when processing a cross-site request forgery request targeting an administrator session. A remote attacker can cause an administrator to submit a specially crafted request to execute arbitrary code.
User interaction is required, and exploitation occurs through cross-site request forgery against an administrator.