CVE-2019-19456 [Suggested Description] --------------------------------------- A pre-auth Reflected XSS vulnerability was found in the server selection box inside the login page. --------------------------------------- [Vulnerability Type] Cross-Site Scripting --------------------------------------- [Vendor of Product] Wowza Media Systems LLC --------------------------------------- [Affected Product Code Base] Wowza Streaming Engine - Versions prior to 4.8.0, Issue fixed in 4.8.0 --------------------------------------- [Affected Component] Wowza Streaming Engine Manager --------------------------------------- [Attack Type] Remote --------------------------------------- [Impact Code Execution] true --------------------------------------- [Impact Denial of Service] false --------------------------------------- [Attack Vector] Embedded script in Wowza Streaming Engine URL field in login form could be executed on failed login --------------------------------------- [Has the vendor confirmed or acknowledged the vulnerability?] true