Kaltura HTML5 播放器(mwEmbed / html5lib)存在一个未认证的远程代码执行漏洞,该漏洞由不安全的反序列化操作和未经验证的文件系统路径构造所导致。mwEmbedLoader.php 会接受用户可控的 ServiceUrl 参数,并将其响应直接传递给 unserialize() 函数进行反序列化。反序列化后生成的对象字段会被写入一个缓存路径,该路径由攻击者提供的 uiconf_id 拼接而成,且未进行正确的路径校验。攻击者可利用此漏洞将任意文件写入 Web 可访问目录,并以 Web 服务器用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kaltura | Kaltura HTML5 Video Player, html5 library | ≤ v2.103 |
affected |
2.45 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kaltura | Kaltura HTML5 Video Player, html5 library | 0 ~ v2.103 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet