Skip to main content

Vendor/product archive

kaltura / kaltura_server CVEs

Beta · best-effort

5 CVEs tagged to kaltura / kaltura_server1 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2017-14143

Published Sep 19, 2017

The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protectio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14142

Published Sep 19, 2017

Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14141

Published Sep 19, 2017

The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6392

Published Mar 2, 2017

An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "server-Lynx-12.11.0/admin_cons…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6391

Published Mar 2, 2017

An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "admin_console/web/tools/Simple…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1