CVE-2019-19454

CVE-2019-19454 - WOWZA Streaming Engine

Vulnerability Description: Arbitrary File Download
Software Version: Wowza Streaming Engine < 4.x.x
NIST: https://nvd.nist.gov/vuln/detail/CVE-2019-19454
CVSv3: 7.5
Severity: High
Credits: Francesco Giordano, Massimiliano Brolli

An arbitrary file download was found in the "Download Log" functionality at
https://[host]/enginemanager/server/logs/download