← Back to CVEs
CVE-2021-35491
HIGH8.1
Description
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.
CVE Details
CVSS v3.1 Score8.1
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
Published10/5/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
wowza:streaming_engine
Weaknesses (CWE)
CWE-352
References
https://n4nj0.github.io/advisories/wowza-streaming-engine-i/(cve@mitre.org)
https://www.gruppotim.it/redteam(cve@mitre.org)
https://n4nj0.github.io/advisories/wowza-streaming-engine-i/(af854a3a-2127-422b-91ae-364da2661108)
https://www.gruppotim.it/redteam(af854a3a-2127-422b-91ae-364da2661108)
https://www.wowza.com/docs/wowza-streaming-engine-4-8-14-release-notes(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.