6.5
CVSSv2

CVE-2017-14141

Published: 19/09/2017 Updated: 17/10/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The wiki_decode Developer System Helper function in the admin panel in Kaltura prior to 13.2.0 allows remote malicious users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kaltura kaltura server

Exploits

Kaltura versions 1310 and below suffer from code execution and cross site scripting vulnerabilities ...