Telestream Tektronix Medius before 10.7.5 and Sentry before 10.7.5 have a SQL injection vulnerability allowing an unauthenticated attacker to dump database contents via the page parameter in a pagelogin request to index.php (aka the server login page).
Publication date: Tue, 22 Sep 2020 17:15:00 +0000