Description
Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.
Published: 2026-03-15
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Wowza Streaming Engine version 4.5.0 contains multiple reflected cross‑site scripting vulnerabilities in its enginemanager interface. Input supplied through parameters such as appName, vhost, uiAppType, and wowzaCloudDestinationType is not properly sanitized before being returned to the browser, allowing an attacker to inject arbitrary HTML and JavaScript. The flaw aligns with CWE‑79 – Improper Neutralization of Input During Web Page Generation. Based on the description, it is inferred that malicious script execution could lead to session hijacking, credential theft, or user‑interface defacement when a user views a crafted page.

Affected Systems

The only affected product identified by the CNA is Wowza Media Systems, LLC’s Wowza Streaming Engine 4.5.0, as specified by the CPE string cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*. No other versions are listed as vulnerable; therefore any installation running exactly version 4.5.0 remains exposed.

Risk and Exploitability

The CVSS score of 5.1 places this flaw in the medium‑severity range. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the web interface; an attacker can craft a malicious request containing script payloads in the vulnerable parameters, which are then reflected back to the user’s browser. If a user interacts with the crafted URL or form, the injected script executes with the privileges of the user’s session, potentially enabling credential theft or other malicious actions.

Generated by OpenCVE AI on March 19, 2026 at 16:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Wowza Media Systems’ website for an official patch or newer release that removes the vulnerability
  • Apply the patch or upgrade to a fixed, non‑vulnerable version if available
  • Implement strict input validation or output encoding on the enginemanager interface to neutralize script injection attempts
  • Configure a Content‑Security‑Policy header to restrict execution of inline scripts on the management pages
  • Monitor web application logs for unexpected script activity or repeated attempts to exploit XSS vectors

Generated by OpenCVE AI on March 19, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 15 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
Description Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through parameters like appName, vhost, uiAppType, and wowzaCloudDestinationType in multiple endpoints to execute arbitrary HTML and JavaScript in a user's browser session.
Title Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities
First Time appeared Wowza
Wowza streaming Engine
Weaknesses CWE-79
CPEs cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*
Vendors & Products Wowza
Wowza streaming Engine
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Wowza Streaming Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-16T14:30:29.820Z

Reserved: 2026-03-15T18:22:32.983Z

Link: CVE-2016-20036

cve-icon Vulnrichment

Updated: 2026-03-16T14:20:59.722Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-16T14:17:50.883

Modified: 2026-03-19T14:17:47.760

Link: CVE-2016-20036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T14:01:22Z

Weaknesses