Back

CRITICAL

Kaltura < 11.1.0-2 PHP Object Injection RCE

Published Jul 23, 2025

Description

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP object in the kdata GET parameter to the redirectWidgetCmd endpoint. Successful exploitation leads to execution of arbitrary PHP code in the context of the web server process.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 23, 2025
Updated Jul 15, 2026
Reserved Jul 22, 2025
CISA Vulnrichment
Updated Jul 24, 2025
NVD
Status Deferred
Modified Jul 15, 2026
Red Hat
Severity n/a
Public date n/a