Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center CERTCC has disclosed two unpatched vulnerabilities in Kalturas HTML5 video player library that allow a remote unauthenticated attacker to read arbitrary files from a server and execute code on it The flaws tracked as CVE202619913 and CVE202619912 both stem from the same unsafe deserialization in the mwEmbedLoaderphp endpoint of the mwEmbed player