First published: Thu Mar 01 2018(Updated: )
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causing script injection and/or reflection via a crafted HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | <4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7049 is a Cross-Site Scripting (XSS) vulnerability in Wowza Streaming Engine before version 4.7.1.
CVE-2018-7049 has a severity rating of 6.1 (medium).
CVE-2018-7049 affects Wowza Streaming Engine versions before 4.7.1 through a Cross-Site Scripting (XSS) vulnerability in the HTTP providers.
To fix CVE-2018-7049, you should upgrade Wowza Streaming Engine to version 4.7.1 or later.
You can find more information about CVE-2018-7049 in the official CVE-2018-7049.txt advisory on GitHub and the Wowza Streaming Engine 4.7.1 release notes.