PT-2020-20350 · Telestream · Telestream Tektronix Sentry+1

Matt Bell

·

Published

2020-09-22

·

Updated

2025-05-01

·

CVE-2020-8887

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telestream Tektronix Medius versions prior to 10.7.5 Telestream Tektronix Sentry versions prior to 10.7.5
Description The issue allows an unauthenticated attacker to perform SQL injection, enabling them to dump database contents. This is achieved by exploiting the page parameter in a page=login request to the "index.php" endpoint, specifically targeting the server login page.
Recommendations For Telestream Tektronix Medius versions prior to 10.7.5, update to version 10.7.5 or later. For Telestream Tektronix Sentry versions prior to 10.7.5, update to version 10.7.5 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-8887
GHSA-G69R-8JWH-2462

Affected Products

Telestream Tektronix Medius
Telestream Tektronix Sentry