CVE-2016-20035

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-16 14:17

Updated : 2026-03-19 14:17


NVD link : CVE-2016-20035

Mitre link : CVE-2016-20035

CVE.ORG link : CVE-2016-20035


JSON object : View

Products Affected

wowza

  • streaming_engine
CWE
CWE-352

Cross-Site Request Forgery (CSRF)