CVE-2026-33024 | WWBN AVideo-Encoder up to 7.x Endpoint getImage.php base64Url server-side request forgery (GHSA-h9gh-866r-6vgq)
A vulnerability was found in WWBN AVideo-Encoder up to 7.x. It has been rated as critical. This affects an unknown part of the file getImage.php of the component Endpoint. Performing a manipulation of the argument base64Url results in server-side request forgery.
This vulnerability is identified as CVE-2026-33024. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.