Vulnerabilities > Wowza > Streaming Engine > 4.7.5

DATE CVE VULNERABILITY TITLE RISK
2020-01-29 CVE-2019-7655 Cross-site Scripting vulnerability in Wowza Streaming Engine
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serversetup/edit_adv.htm of the Server Setup configuration or the (2) host field in enginemanager/j_spring_security_check of the login form.
network
low complexity
wowza CWE-79
5.4
2020-01-29 CVE-2019-7654 Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities.
network
low complexity
wowza CWE-352
6.5