PT-2026-25734 · Wowza · Streaming Engine

CVE-2016-20036

·

Publicado

2026-03-15

·

Atualizado

2026-03-16

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wowza Streaming Engine version 4.5.0
Description The software contains multiple reflected cross-site scripting issues in the enginemanager interface. Input provided through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters such as appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.
Recommendations Ensure proper sanitization of the appName parameter. Ensure proper sanitization of the vhost parameter. Ensure proper sanitization of the uiAppType parameter. Ensure proper sanitization of the wowzaCloudDestinationType parameter.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-20036

Produtos afetados

Streaming Engine