Critical Vulnerabilities in AVideo: From SQL Injection to Remote Code Execution
ID: 7153379e-3115-5bb4-a30c-95dfad369267
STIX ID: report--7153379e-3115-5bb4-a30c-95dfad369267
Feed Name: securityonline.info
**Executive Summary:** Security researchers disclosed two high-severity vulnerabilities in the AVideo open-source streaming platform: CVE-2026-28501 (unauthenticated SQL injection, CVSS 9.8) that can enable database exfiltration and credential theft, and CVE-2026-28502 (authenticated plugin upload RCE) that permits full system compromise via malicious ZIP uploads; users are urged to upgrade to AVideo v23+ or apply mitigations such as disabling plugin imports and hardening web server execution permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
