CVE-2017-6392: XSS
An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "server-Lynx-12.11.0/adminconsole/web/tools/XmlJWPlayer.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6392?
CVE-2017-6392 has been classified as a high severity vulnerability due to the potential for executing arbitrary code.
How do I fix CVE-2017-6392?
To fix CVE-2017-6392, you should update Kaltura server to the latest version beyond Lynx-12.11.0 that addresses this issue.
What type of vulnerability is CVE-2017-6392?
CVE-2017-6392 is an input validation vulnerability that allows attackers to inject arbitrary HTML and script code.
In which software versions does CVE-2017-6392 exist?
CVE-2017-6392 affects Kaltura server versions up to and including Lynx-12.11.0.
What can an attacker achieve with CVE-2017-6392?
An attacker exploiting CVE-2017-6392 can execute arbitrary code in the victim's browser, leading to potential data theft or site compromise.