CVE-2019-7654
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into making unwanted changes such as adding another admin user via enginemanager/server/user/edit.htm in the Server->Users component. This issue was resolved in Wowza Streaming Engine 4.8.5.
Wowza Streaming Engine versiones 4.8.0 y anteriores, sufre de múltiples vulnerabilidades de tipo CSRF. Por ejemplo, un administrador, al seguir un enlace, puede ser engañado para hacer cambios no deseados, como agregar otro usuario administrador por medio del archivo enginemanager/server/user/edit.htm en el componente Server->Users. Este problema se resolvió en Wowza Streaming Engine 4.8.5
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-08 CVE Reserved
- 2020-01-29 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://raw.githubusercontent.com/WowzaMediaSystems/public_cve/main/wowza-streaming-engine/CVE-2019-7654.txt | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-7654-CSRF-Wowza | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.wowza.com/docs/wowza-streaming-engine-4-8-5-release-notes | 2022-10-14 | |
https://www.wowza.com/pricing/installer | 2022-10-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wowza Search vendor "Wowza" | Streaming Engine Search vendor "Wowza" for product "Streaming Engine" | <= 4.8.0 Search vendor "Wowza" for product "Streaming Engine" and version " <= 4.8.0" | - |
Affected
|