PT-2026-25733 · Wowza · Streaming Engine
Published
2026-03-15
·
Updated
2026-03-16
·
CVE-2016-20035
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wowza Streaming Engine version 4.5.0
Description
The software contains a cross-site request forgery issue that allows attackers to perform administrative actions by creating malicious web pages. Attackers can deceive logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new administrator accounts with arbitrary credentials. The vulnerable endpoint is
/user edit. The credentials used for the new admin accounts can be set arbitrarily by the attacker.Recommendations
Apply a fix or update to a newer version that addresses this cross-site request forgery issue. As a temporary workaround, consider restricting access to the
/user edit endpoint to authorized IP addresses only.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Streaming Engine