VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
Imported from official source
Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. …
This version
- Version
- 1 of 2
- Recorded
- September 15, 2026 20:57
- Change
- Initial
- Content hash
c0d7907b8c79c7f0f7cda4a41f20b397- All versions
- Revision history