news.mlab.sh
7 results
vulnerability

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Two unpatched vulnerabilities in Kaltura's HTML5 video player library (mwEmbed) allow remote attackers to read arbitrary files and execute code on a server, without requiring authentication. These flaws stem from unsafe deserialization and can be exploited even if the player is hosted on Kaltura's shared CDN infrastruc…

The Hacker News · 4d ago High