WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true, enabling cross-origin session theft and full account takeover. This issue has been fixed in version 26.0.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qc3p-398r-p59j | AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Vendors & Products |
Wwbn
Wwbn avideo |
Fri, 20 Mar 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true, enabling cross-origin session theft and full account takeover. This issue has been fixed in version 26.0. | |
| Title | AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-20T05:52:59.412Z
Reserved: 2026-03-17T18:10:50.211Z
Link: CVE-2026-33043
No data.
Status : Undergoing Analysis
Published: 2026-03-20T06:16:12.670
Modified: 2026-03-20T13:37:50.737
Link: CVE-2026-33043
No data.
OpenCVE Enrichment
Updated: 2026-03-20T10:37:03Z
Weaknesses
Github GHSA