CVE-2016-20035

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*

History

19 Mar 2026, 14:17

Type Values Removed Values Added
CPE cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*
First Time Wowza
Wowza streaming Engine
References () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5341.php - () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5341.php - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/40134 - () https://www.exploit-db.com/exploits/40134 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/wowza-streaming-engine-csrf-via-user-edit-endpoint - () https://www.vulncheck.com/advisories/wowza-streaming-engine-csrf-via-user-edit-endpoint - Third Party Advisory
Summary
  • (es) Wowza Streaming Engine 4.5.0 contiene una vulnerabilidad de falsificación de petición en sitios cruzados que permite a los atacantes realizar acciones administrativas mediante la elaboración de páginas web maliciosas. Los atacantes pueden engañar a los administradores que han iniciado sesión para que visiten un sitio malicioso que envía peticiones POST al punto final de edición de usuario para crear nuevas cuentas de administrador con credenciales arbitrarias.

16 Mar 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:17

Updated : 2026-03-19 14:17


NVD link : CVE-2016-20035

Mitre link : CVE-2016-20035

CVE.ORG link : CVE-2016-20035


JSON object : View

Products Affected

wowza

  • streaming_engine
CWE
CWE-352

Cross-Site Request Forgery (CSRF)