CVE-2016-20036 PUBLISHED

Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities

Assigner: VulnCheck
Reserved: 15.03.2026 Published: 15.03.2026 Updated: 16.03.2026

Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Wowza Media Systems, LLC.
Product Wowza Streaming Engine
Versions
  • Version 4.5.0 is affected

Credits

  • LiquidWorm as Gjoko Krstic of Zero Science Lab finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE