CVE-2017-14143 is a critical vulnerability affecting Kaltura before version 13.2.0, stemming from the use of a hardcoded cookie secret in the getUserzoneCookie function. This flaw allows remote attackers to bypass security mechanisms, leading to PHP object injection and arbitrary PHP code execution. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, potentially resulting in complete compromise of confidentiality, integrity, and availability. While not on the KEV catalog or actively exploited, public exploit code, including a Metasploit module, is available, and its high EPSS score indicates a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= mercury-13.1.0CPE matchmatch criteria | cpe:2.3:a:kaltura:kaltura_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.