Vulnerabilities (CVE)

Filtered by vendor Kaltura Subscribe
Filtered by product Kaltura Server
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14143 1 Kaltura 1 Kaltura Server 2018-01-27 7.5 HIGH 9.8 CRITICAL
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and execute arbitrary PHP code via a crafted userzone cookie.