Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Yairans

#55107of 56,330
4Total CVSS
Vulnerabilities · 1
PT-2023-15890
4.0
2023-01-04
Kaltura · Kaltura Mwembed · CVE-2022-4876
**Name of the Vulnerable Software and Affected Versions** Kaltura mwEmbed versions up to 2.96.rc1 **Description** A vulnerability was found in Kaltura mwEmbed, affecting some unknown processing of the file includes/DefaultSettings.php. The manipulation of the argument `HTTP X FORWARDED HOST` leads to cross-site scripting. The attack may be initiated remotely. **Recommendations** For Kaltura mwEmbed versions up to 2.96.rc1, upgrade to version 2.96.rc2 to address this issue.