Kaltura HTML5 播放器(mwEmbed / html5lib)存在本地文件披露漏洞。该漏洞源于 mwEmbedLoader.php 中对 ServiceUrl 参数验证不当。此参数被用作后端请求的基础 URL,并允许使用 file:// 等非 HTTP 协议。当发生异常或错误时,响应内容会被反序列化,其原始内容会通过错误消息反射返回给客户端;这使得未认证的远程攻击者能够读取服务器可达的任意内部文件。受影响的版本包括 html5lib v2.45、v2.103 及更早版本,以及其他 v2.x 系列中暴露了
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Kaltura | Kaltura HTML5 Video Player, html5lib library | ≤ v2.103 |
affected |
2.45 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kaltura | Kaltura HTML5 Video Player, html5lib library | 0 ~ v2.103 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet