CVE-2019-7654

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
29/01/2020
Last modified:
14/10/2022

Description

Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:* 4.8.0 (including)