Impact
The vulnerability lies in the /callrec/audio.jsp page of Eleveo Call Recording Software 9.7.0, where the viewRoleId or cfType parameters are not validated, allowing an attacker to inject malicious script. When a victim loads the page, the injected code executes in their browser, enabling theft of session cookies, defacement, or additional client‑side attacks. This flaw is a reflected XSS that can be leveraged to compromise user interaction with the application.
Affected Systems
Any installation of Eleveo Call Recording Software version 9.7.0 that hosts the proprietary call‑recording solution is impacted. The flaw affects the Play Audio Page component accessible via web interface.
Risk and Exploitability
The CVSS score of 5.1 places the weakness in the medium range, and no EPSS value is available, indicating limited data on recent exploitation. Nonetheless, an exploit has been published and the flaw is remotely exploitable with no local privilege requirement. A crafted URL is sufficient, allowing an adversary with network visibility to target exposed instances. The vulnerability is not listed in CISA’s KEV catalog, but the publicly available exploit suggests that affected systems may see similar exploitation activity.
OpenCVE Enrichment