CVE-2016-20035

Severity CVSS v4.0:
MEDIUM
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
16/03/2026
Last modified:
19/03/2026

Description

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*