Security Advisory

CVE-2016-20035

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-03-15 18:34:22
Last updated 2026-03-16 14:30:30
Assigner VulnCheck
State PUBLISHED

Description

Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.