Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6v2j-9827-hp4v

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request.

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request.

EPSS

Процентиль: 42%
0.00199
Низкий

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.

EPSS

Процентиль: 42%
0.00199
Низкий

Дефекты

CWE-352