Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33867

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the database (via SQL injection, a database backup, or misconfigured access controls), they obtain all video passwords in cleartext. Commit f2d68d2adbf73588ea61be2b781d93120a819e36 contains a patch.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Версия до 26.0 (включая)

EPSS

Процентиль: 5%
0.00152
Низкий

7.5 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

github
6 месяцев назад

AVideo has Plaintext Video Password Storage

EPSS

Процентиль: 5%
0.00152
Низкий

7.5 High

CVSS3

Дефекты

CWE-312