Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 15 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session. | |
| Title | Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities | |
| First Time appeared |
Wowza
Wowza streaming Engine |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Wowza
Wowza streaming Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-15T18:34:23.829Z
Reserved: 2026-03-15T18:22:32.983Z
Link: CVE-2016-20036
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses