PHP Object Injection Vulnerability in Kaltura Admin Panel
CVE-2017-14141
7.2HIGH
What is CVE-2017-14141?
The Kaltura Developer System has a critical vulnerability in its admin panel's wiki_decode function. This flaw enables remote attackers to exploit PHP object injection attacks, posing serious risks by allowing unauthorized execution of arbitrary PHP code through specially crafted serialized objects. Users are advised to upgrade to version 13.2.0 or later to mitigate this security concern.
