Vulnerabilities > CVE-2017-14141 - Deserialization of Untrusted Data vulnerability in Kaltura Server
Attack vector
NETWORK Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/144304/kaltura-xssexec.txt |
id | PACKETSTORM:144304 |
last seen | 2017-09-26 |
published | 2017-09-23 |
reporter | Robin Verton |
source | https://packetstormsecurity.com/files/144304/Kaltura-13.1.0-Code-Execution-Cross-Site-Scripting.html |
title | Kaltura 13.1.0 Code Execution / Cross Site Scripting |
References
- http://www.securityfocus.com/bid/100976
- http://www.securityfocus.com/bid/100976
- https://github.com/kaltura/server/commit/6a6d14328b7a1493e8c47f9565461e5f88be20c9#diff-0770640cc76112cbf77bebc604852682
- https://github.com/kaltura/server/commit/6a6d14328b7a1493e8c47f9565461e5f88be20c9#diff-0770640cc76112cbf77bebc604852682
- https://telekomsecurity.github.io/assets/advisories/20170912_kaltura-advisory.txt
- https://telekomsecurity.github.io/assets/advisories/20170912_kaltura-advisory.txt