CVE-2019-7654 [Suggested Description] --------------------------------------- The Wowza Streaming Engine Manager application has multiple CSRF vulnerabilities. --------------------------------------- [Vulnerability Type] Cross-Site Request Forgery --------------------------------------- [Vendor of Product] Wowza Media Systems LLC --------------------------------------- [Affected Product Code Base] Wowza Streaming Engine - Version 4.8.0 and earlier, Issue fixed in 4.8.5 --------------------------------------- [Affected Component] Wowza Streaming Engine Manager --------------------------------------- [Attack Type] Remote --------------------------------------- [Impact Code Execution] true --------------------------------------- [Impact Denial of Service] false --------------------------------------- [Attack Vector] An authenticated admin user, by following a link, could be tricked into making unwanted changes like adding another admin user. --------------------------------------- [Has the vendor confirmed or acknowledged the vulnerability?] true