CVE-2017-14142: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/adminconsole/web/tools/bigRedButton.php; the (3) partnerId, (4) playerVersion, (5) secret, (6) entryId, (7) adminUiConfId, or (8) uiConfId parameter to server/adminconsole/web/tools/bigRedButtonPtsPoc.php; the (9) streamUsername, (10) streamPassword, (11) streamRemoteId, (12) streamRemoteBackupId, or (13) entryId parameter to server/adminconsole/web/tools/AkamaiBroadcaster.php; the (14) entryId parameter to server/adminconsole/web/tools/XmlJWPlayer.php; or the (15) partnerId or (16) playerVersion parameter to server/alpha/web/lib/bigRedButtonPtsPocHlsjs.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14142?
CVE-2017-14142 is classified as a moderate severity vulnerability due to its ability to enable cross-site scripting (XSS) attacks.
How do I fix CVE-2017-14142?
To fix CVE-2017-14142, upgrade your Kaltura Server to version 13.2.0 or later.
What types of vulnerabilities does CVE-2017-14142 include?
CVE-2017-14142 includes multiple cross-site scripting (XSS) vulnerabilities.
Which versions of Kaltura are affected by CVE-2017-14142?
CVE-2017-14142 affects Kaltura Server versions prior to 13.2.0.
How can CVE-2017-14142 be exploited?
CVE-2017-14142 can be exploited by injecting arbitrary web scripts or HTML via specific parameters in the application.