First published: Wed Jan 29 2020(Updated: )
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | <=4.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7654 is a vulnerability in Wowza Streaming Engine 4.8.0 and earlier that allows for CSRF attacks.
CVE-2019-7654 has a severity rating of medium with a CVSS score of 6.5.
The CWE ID for CVE-2019-7654 is 352.
An attacker can exploit CVE-2019-7654 by tricking an administrator into making unwanted changes, such as adding another admin user, through a CSRF attack.
Yes, a patch is available for CVE-2019-7654 in Wowza Streaming Engine 4.8.5.