Wowza Streaming Engine
cpe:2.3:a:wowza:streaming_engine:*:*:*:*:*:*:*
- 4.5.0 (build 18676)
A privilege escalation vulnerability exists in Wowza Streaming Engine version 4.5.0. This vulnerability allows authenticated read-only users to gain administrative privileges by manipulating POST parameters. By sending requests to the user edit endpoint with the accessLevel parameter set to 'admin' and the advUser parameters set to 'true' and 'on', users can elevate their rights to that of an administrator.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling read-only users to gain administrative rights on the server.
To reproduce this vulnerability, send a POST request to the user edit endpoint of the Wowza Streaming Engine management interface. Include the accessLevel parameter set to 'admin' and the advUser parameters set to 'true' and '_advUser' set to 'on'. This will grant the user administrative access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.