The wiki_decode Developer System Helper function in the admin panel in Kaltura prior to 13.2.0 allows remote malicious users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
kaltura kaltura server |