CVE-2019-7655 [Suggested Description] --------------------------------------- Wowza Streaming Engine has multiple authenticated XSS vulnerabilities. --------------------------------------- [Vulnerability Type] Cross-Site Scripting --------------------------------------- [Vendor of Product] Wowza Media Systems LLC --------------------------------------- [Affected Product Code Base] Wowza Streaming Engine - Version 4.8.0 and earlier, Issue fixed in 4.8.5 --------------------------------------- [Affected Component] Wowza Streaming Engine Manager --------------------------------------- [Attack Type] Remote --------------------------------------- [Impact Code Execution] true --------------------------------------- [Impact Denial of Service] false --------------------------------------- [Attack Vector] An authenticated user is able to insert a malicious payload that will be triggered in the Server Setup and login forms. --------------------------------------- [Has the vendor confirmed or acknowledged the vulnerability?] true