SQL injection in AVideo - CVE-2026-33651
Published: May 4, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to sql injection in Scheduler_commands::getAllActiveOrToRepeat() when handling a crafted live_schedule_id value through the remindMe.json.php endpoint. A remote user can send a specially crafted request to disclose sensitive information and modify data.
The issue is exploitable through time-based blind techniques, and no user interaction is required.