CVE-2016-15044 is a critical remote code execution vulnerability affecting Kaltura versions prior to 11.1.0-2. This flaw stems from unsafe deserialization of user-controlled data within the keditorservices module, specifically when processing the kdata GET parameter sent to the redirectWidgetCmd endpoint. An unauthenticated attacker can exploit this with low complexity, leading to arbitrary PHP code execution in the context of the web server process, resulting in complete compromise of confidentiality, integrity, and availability. Exploit code, including a Metasploit module, is publicly available, and the vulnerability has garnered significant community discussion, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kaltura | Video Platform | >= 0, < 11.1.0-2CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.