The CERT Coordination Center CERTCC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE202619913 and CVE202619912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity