← Volver a CVEs
CVE-2021-35491
HIGH8.1
Descripcion
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.
Detalles CVE
Puntuacion CVSS v3.18.1
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado10/5/2021
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
wowza:streaming_engine
Debilidades (CWE)
CWE-352
Referencias
https://n4nj0.github.io/advisories/wowza-streaming-engine-i/(cve@mitre.org)
https://www.gruppotim.it/redteam(cve@mitre.org)
https://n4nj0.github.io/advisories/wowza-streaming-engine-i/(af854a3a-2127-422b-91ae-364da2661108)
https://www.gruppotim.it/redteam(af854a3a-2127-422b-91ae-364da2661108)
https://www.wowza.com/docs/wowza-streaming-engine-4-8-14-release-notes(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.