PT-2026-25733 · Wowza · Streaming Engine

Published

2026-03-15

·

Updated

2026-03-16

·

CVE-2016-20035

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wowza Streaming Engine version 4.5.0
Description The software contains a cross-site request forgery issue that allows attackers to perform administrative actions by creating malicious web pages. Attackers can deceive logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new administrator accounts with arbitrary credentials. The vulnerable endpoint is /user edit. The credentials used for the new admin accounts can be set arbitrarily by the attacker.
Recommendations Apply a fix or update to a newer version that addresses this cross-site request forgery issue. As a temporary workaround, consider restricting access to the /user edit endpoint to authorized IP addresses only.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2016-20035

Affected Products

Streaming Engine