CVE-2024-10276

A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://vuldb.com/?ctiid.281551 Permissions Required VDB Entry
https://vuldb.com/?id.281551 Third Party Advisory VDB Entry
https://vuldb.com/?submit.423695 Exploit Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:telestream:sentry:6.0.9:*:*:*:*:*:*:*

History

01 May 2025, 14:37

Type Values Removed Values Added
First Time Telestream sentry
Telestream
CPE cpe:2.3:a:telestream:sentry:6.0.9:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://vuldb.com/?id.281551 - () https://vuldb.com/?id.281551 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?ctiid.281551 - () https://vuldb.com/?ctiid.281551 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.423695 - () https://vuldb.com/?submit.423695 - Exploit, Mitigation, Third Party Advisory

29 Oct 2024, 18:15

Type Values Removed Values Added
Summary A vulnerability has been found in Tektronix Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports of the component Reports Page. The manipulation of the argument z leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

23 Oct 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-23 11:15

Updated : 2025-05-01 14:37


NVD link : CVE-2024-10276

Mitre link : CVE-2024-10276


JSON object : View

Products Affected

telestream

  • sentry
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')