Description
Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the user edit endpoint to create new admin accounts with arbitrary credentials.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/40134 (ExploitDB-40134)
www.zeroscience.mk/en/vulnerabilities/ZSL-2016-5341.php (Vulnerability Advisory)
www.vulncheck.com/...ming-engine-csrf-via-user-edit-endpoint (VulnCheck Advisory: Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint)