First published: Tue Oct 05 2021(Updated: )
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wowza Streaming Engine | <4.8.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35491 is a Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine that allows a remote attacker to delete a user account.
CVE-2021-35491 has a severity score of 8.1, which is considered high.
CVE-2021-35491 works by exploiting a lack of CSRF token implementation in Wowza Streaming Engine, which allows an attacker to manipulate the /enginemanager/server/user/delete.htm userName parameter to delete a user account.
Wowza Streaming Engine versions up to and including 4.8.14 are affected by CVE-2021-35491.
Yes, the issue was resolved in Wowza Streaming Engine 4.8.14.