CVE-2017-6391: XSS
An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "adminconsole/web/tools/SimpleJWPlayer.php" URL, the "adminconsole/web/tools/AkamaiBroadcaster.php" URL, the "adminconsole/web/tools/bigRedButton.php" URL, and the "adminconsole/web/tools/bigRedButtonPtsPoc.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6391?
CVE-2017-6391 is considered a medium-severity vulnerability affecting Kaltura server versions up to Lynx-12.11.0.
How do I fix CVE-2017-6391?
To fix CVE-2017-6391, upgrade your Kaltura server to a version that is not affected, as indicated in the vendor's security advisory.
What type of vulnerability is identified in CVE-2017-6391?
CVE-2017-6391 is a web application vulnerability due to insufficient filtration of user-supplied data.
Which software versions are affected by CVE-2017-6391?
Kaltura server versions up to and including Lynx-12.11.0 are affected by CVE-2017-6391.
Where can I find more information about CVE-2017-6391?
Additional information about CVE-2017-6391 can typically be found in security bulletins or the official Kaltura repository.