CVE-2016-20035
MEDIUMWowza Streaming Engine 4.5.0 CSRF via user edit endpoint
Title source: cnaDescription
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
Exploits (1)
Scores
CVSS v3
5.3
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Details
CWE
CWE-352
Status
published
Products (2)
wowza/streaming_engine
4.5.0
Wowza Media Systems, LLC./Wowza Streaming Engine
4.5.0
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026