vendor:
Kaltura
by:
Security-Assessment.com, Mehmet Ince
N/A
CVSS
N/A
Object Injection
502
CWE
Product Name: Kaltura
Affected Version From: Kaltura 11.1.0
Affected Version To: Kaltura 11.1.0-2
Patch Exists: YES
Related CWE: EDB-39563
CPE: a:kaltura:kaltura
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS 6.8
2016
Kaltura Remote PHP Code Execution
This module exploits an Object Injection vulnerability in Kaltura. By exploiting this vulnerability, unauthenticated users can execute arbitrary code under the context of the web server user. Kaltura has a module named keditorservices that takes user input and then uses it as an unserialized function parameter. The constructed object is based on the SektionEins Zend code execution POP chain PoC, with a minor modification to ensure Kaltura processes it and the Zend_Log function's __destruct() method is called. Kaltura versions prior to 11.1.0-2 are affected by this issue.
Mitigation:
Upgrade to Kaltura version 11.1.0-2 or later