LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2016-20034

wowza · streaming engine

Published
CVSS8.8
Severityhigh
WeaknessCWE-352
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.

References

← Back to the CVE Tracker

Our coverage of CVE-2016-20034

No stories yet. This page updates automatically when we publish reporting that references CVE-2016-20034.