Security Advisory

CVE-2016-20034

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-15 18:34:22
Last updated 2026-03-16 14:30:30
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin' and advUser parameters set to 'true' and 'on' to gain administrative access.