Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yairans

#43477de 53,634
6.1CVSS total
Vulnerabilidades · 1
PT-2023-15890
6.1
2023-01-04
Kaltura · Kaltura Mwembed · CVE-2022-4876
**Name of the Vulnerable Software and Affected Versions** Kaltura mwEmbed versions up to 2.96.rc1 **Description** A vulnerability was found in Kaltura mwEmbed, affecting some unknown processing of the file includes/DefaultSettings.php. The manipulation of the argument `HTTP X FORWARDED HOST` leads to cross-site scripting. The attack may be initiated remotely. **Recommendations** For Kaltura mwEmbed versions up to 2.96.rc1, upgrade to version 2.96.rc2 to address this issue.