CVE-2019-19456: XSS
Published May 18, 2020
·Updated
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.
Affected Software
1 affected component
Wowza Streaming Engine>=4.0.0<=4.8.0
Event History
May 18, 2020
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this XSS vulnerability?
The vulnerability ID is CVE-2019-19456.
2
Where was the XSS vulnerability found?
The XSS vulnerability was found in the server selection box inside the login page of Wowza Streaming Engine <= 4.x.x.
3
What version of Wowza Streaming Engine is affected by this vulnerability?
Wowza Streaming Engine versions between 4.0.0 and 4.8.0 are affected by this vulnerability.
4
How severe is this XSS vulnerability?
This XSS vulnerability has a severity rating of medium, with a CVSS score of 6.1.
5
How can I fix this XSS vulnerability?
You can fix this XSS vulnerability by updating Wowza Streaming Engine to version 4.8.0 or later.