Medium severity6.1NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026
CVE-2016-20036
CVE-2016-20036
Description
Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34.5.0+ 1 more
- (no CPE)range: 4.5.0
- cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*
- Wowza Media Systems, LLC./Wowza Streaming Enginev5Range: 4.5.0
Patches
Vulnerability mechanics
References
3- www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5343.phpnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/40135nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/wowza-streaming-engine-multiple-cross-site-scripting-vulnerabilitiesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.