Ad

CVE-2016-20034

HIGH CVSS 4.0: 8.7 EPSS 0.03%
Updated Mar 19, 2026
Wowza Streaming
Parameter Value
CVSS 8.7 (HIGH)
Type CWE-352 (Cross-Site Request Forgery (CSRF))
Vendor Wowza Streaming
Public PoC Yes

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Wowza Streaming_Engine
cpe:2.3:a:wowza:streaming_engine:4.5.0:*:*:*:*:*:*:*