Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 22 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wowza
Wowza streaming Engine
CPEs cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*:*
Vendors & Products Wowza
Wowza streaming Engine
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 22:45:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.
Title Stored Cross-Site Scripting in Wowza Streaming Engine
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-11-22T16:10:58.456Z

Reserved: 2024-11-05T16:58:15.300Z

Link: CVE-2024-52053

cve-icon Vulnrichment

Updated: 2024-11-22T16:10:49.444Z

cve-icon NVD

Status : Received

Published: 2024-11-21T23:15:05.387

Modified: 2024-11-21T23:15:05.387

Link: CVE-2024-52053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.