VYPR

Streaming Engine

by Wowza

CVEs (26)

  • CVE-2019-19453MedAug 3, 2020
    risk 0.35cvss 5.4epss 0.01

    Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious payload that will be triggered in the main page of server settings. This issue was resolved in Wowza Streaming Engine…

  • CVE-2019-7655MedJan 29, 2020
    risk 0.35cvss 5.4epss 0.01

    Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of…

  • CVE-2017-16922MedMar 5, 2018
    risk 0.35cvss 5.3epss 0.01

    In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of a file are possible via a remote, specifically crafted HTTP request.

  • CVE-2016-20035MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the…

  • CVE-2024-52055MedNov 21, 2024
    risk 0.32cvss 4.9epss 0.01

    Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.

  • CVE-2024-52054LowNov 21, 2024
    risk 0.18cvss 2.7epss 0.01

    Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.

Page 2 of 2