CVE-2019-7655: XSS
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/editadv.htm of the Server Setup configuration or the (2) host field in enginemanager/jspringsecuritycheck of the login form. This issue was resolved in Wowza Streaming Engine 4.8.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7655?
The severity of CVE-2019-7655 is medium with a CVSS score of 5.4.
How does CVE-2019-7655 affect Wowza Streaming Engine?
CVE-2019-7655 affects Wowza Streaming Engine versions up to and including 4.8.0.
What is the vulnerability in CVE-2019-7655?
The vulnerability in CVE-2019-7655 is a multiple authenticated XSS vulnerability.
How can an attacker exploit CVE-2019-7655?
An attacker can exploit CVE-2019-7655 by injecting malicious code via the customList[0].value field or the host field in the login form of Wowza Streaming Engine.
Is there a fix available for CVE-2019-7655?
Yes, the fix for CVE-2019-7655 is included in Wowza Streaming Engine 4.8.5. It is recommended to update to this version to mitigate the vulnerability.