The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-09-19T15:00:00

Updated: 2024-08-05T19:20:41.290Z

Reserved: 2017-09-05T00:00:00

Link: CVE-2017-14141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-09-19T15:29:00.977

Modified: 2019-10-17T20:25:20.263

Link: CVE-2017-14141

cve-icon Redhat

No data.