Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers to execute UNION-based SQL injection to read arbitrary database contents including password hashes and sensitive data. | |
| Title | AVideo User_Location Plugin Unauthenticated SQL Injection | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T22:25:30.493Z
Reserved: 2026-09-01T11:03:27.973Z
Link: CVE-2026-84208
No data.
Status : Received
Published: 2026-09-01T23:17:21.353
Modified: 2026-09-01T23:17:21.353
Link: CVE-2026-84208
No data.
OpenCVE Enrichment
Updated: 2026-09-01T23:30:04Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')