An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList and com.wowza.wms.http.streammanager.HTTPStreamManager) causing script injection and/or reflection via a crafted HTTP request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-01T20:00:00

Updated: 2024-08-05T06:17:17.372Z

Reserved: 2018-02-14T00:00:00

Link: CVE-2018-7049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-01T21:29:00.517

Modified: 2020-10-01T17:15:12.963

Link: CVE-2018-7049

cve-icon Redhat

No data.