Junglewise Threat Intelligence

CVE-2026-85155: WWBN AVideo SQL injection in channels endpoint

CVE-2026-85155 · Severity: high · CVSS 7.5 · Published 2026-09-03

Technologies: WWBN AVideo. Vendors: WWBN.

Executive brief

WWBN AVideo is a video streaming and content management platform. An unauthenticated attacker can manipulate the sort parameter in the channels API endpoint to extract sensitive information like password hashes and recovery tokens by observing how results are ordered, and can also trigger database errors that leak the full SQL query and schema details. This allows attackers to infer user credentials without authentication.

Technical details

The vulnerability is a SQL injection in the ORDER BY clause of get.json.php with APIName=channels, where the sort column name is controlled by the attacker via the columns[0][data] parameter. A regex filter (removes only quotes, parentheses, and commas) permits any valid SQL identifier, allowing selection of columns from joined tables such as users.password and users.recoverPass that are never returned in normal responses. Since the attacker controls both the column and sort direction (ASC/DESC), the ordering of results becomes an oracle over the secret column's values. Additionally, invalid column names trigger MySQL errors that echo the complete SQL statement and database schema. The attack requires no authentication and is reachable over the network. Turning the ordering oracle into full password extraction requires comparison with attacker-controlled values (a known technique but not demonstrated end-to-end in the advisory).

Affected products

  • WWBN AVideo 29.0 and earlier

Timeline

  • 2026-08-19: disclosed: GitHub Security Advisory GHSA-pmmj-6425-gpgh published
  • 2026-09-03: advisory: CVE-2026-85155 published on NVD
  • 2026-09-03: other: VulnCheck advisory published

References

Related threats