CVE-2019-7654: CSRF
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7654?
CVE-2019-7654 is a vulnerability in Wowza Streaming Engine 4.8.0 and earlier that allows for CSRF attacks.
How severe is CVE-2019-7654?
CVE-2019-7654 has a severity rating of medium with a CVSS score of 6.5.
What is the CWE ID for CVE-2019-7654?
The CWE ID for CVE-2019-7654 is 352.
How can an attacker exploit CVE-2019-7654?
An attacker can exploit CVE-2019-7654 by tricking an administrator into making unwanted changes, such as adding another admin user, through a CSRF attack.
Is there a patch available for CVE-2019-7654?
Yes, a patch is available for CVE-2019-7654 in Wowza Streaming Engine 4.8.5.