CVE-2019-19456

CVE-2019-19456 - WOWZA Streaming Engine

Vulnerability Description: Pre-Auth Cross Site Scripting
Software Version: Wowza Streaming Engine < 4.x.x
NIST: https://nvd.nist.gov/vuln/detail/CVE-2019-19456
CVSv3: 6.1
Severity: Medium

Credits: Francesco Giordano, Massimiliano Brolli

A Reflected XSS was found in the server selection box inside the login page at:
http://[host]/enginemanager/loginfailed.html