Medium severity5.3NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026
CVE-2016-20035
CVE-2016-20035
Description
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34.5.0+ 1 more
- (no CPE)range: 4.5.0
- cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*
- Wowza Media Systems, LLC./Wowza Streaming Enginev5Range: 4.5.0
Patches
Vulnerability mechanics
References
3- www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5341.phpnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/40134nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/wowza-streaming-engine-csrf-via-user-edit-endpointnvdThird Party Advisory
News mentions
0No linked articles in our index yet.