vendor:
Wowza Streaming Engine
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Wowza Streaming Engine
Affected Version From: 4.5.0 (build 18676)
Affected Version To: 4.5.0 (build 18676)
Patch Exists: NO
Related CWE: N/A
CPE: a:wowza_media_systems:wowza_streaming_engine
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Winstone Servlet Engine v1.0.5, Servlet/2.5 (Winstone/1.0.5)
2016
Wowza Streaming Engine 4.5.0 Remote Privilege Escalation Exploit
The application suffers from a privilege escalation issue. Normal user (read-only) can elevate his/her privileges by sending a POST request seting the parameter 'accessLevel' to 'admin' gaining admin rights and/or setting the parameter 'advUser' to 'true' and '_advUser' to 'on' gaining advanced admin rights.
Mitigation:
Ensure that the application is configured to use the least privilege necessary for the user to perform their job.