SB20260408172 - Multiple vulnerabilities in AVideo



SB20260408172 - Multiple vulnerabilities in AVideo

Published: April 8, 2026 Updated: April 15, 2026

Security Bulletin ID SB20260408172
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-27732)

The vulnerability allows a remote user to perform server-side requests to arbitrary URLs and disclose sensitive information.

The vulnerability exists due to server-side request forgery in aVideoEncoder.json.php when processing the downloadURL parameter. A remote user can supply a crafted URL to perform server-side requests to arbitrary URLs and disclose sensitive information.

The issue can be used to reach internal network endpoints, including internal APIs and metadata services.


2) SQL injection (CVE-ID: CVE-2026-28501)

The vulnerability allows a remote attacker to execute arbitrary SQL queries and disclose sensitive information.

The vulnerability exists due to sql injection in objects/videos.json.php and objects/video.php when processing the catName parameter from a JSON-formatted POST request body. A remote attacker can send a specially crafted JSON request to execute arbitrary SQL queries and disclose sensitive information.

JSON input is parsed and merged into $_REQUEST after global security checks are executed, allowing the payload to bypass the existing sanitization mechanisms.


Remediation

Install update from vendor's website.