inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.7%