Description
A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (XSS) in Eleveo Call Recording Software 9.7.0
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the /callrec/audio.jsp page of Eleveo Call Recording Software 9.7.0, where the viewRoleId or cfType parameters are not validated, allowing an attacker to inject malicious script. When a victim loads the page, the injected code executes in their browser, enabling theft of session cookies, defacement, or additional client‑side attacks. This flaw is a reflected XSS that can be leveraged to compromise user interaction with the application.

Affected Systems

Any installation of Eleveo Call Recording Software version 9.7.0 that hosts the proprietary call‑recording solution is impacted. The flaw affects the Play Audio Page component accessible via web interface.

Risk and Exploitability

The CVSS score of 5.1 places the weakness in the medium range, and no EPSS value is available, indicating limited data on recent exploitation. Nonetheless, an exploit has been published and the flaw is remotely exploitable with no local privilege requirement. A crafted URL is sufficient, allowing an adversary with network visibility to target exposed instances. The vulnerability is not listed in CISA’s KEV catalog, but the publicly available exploit suggests that affected systems may see similar exploitation activity.

Generated by OpenCVE AI on September 28, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch that validates or encodes the viewRoleId and cfType parameters in Eleveo Call Recording Software 9.7.0.
  • Configure the web server to enforce output encoding on data returned by audio.jsp and restrict access to the Play Audio page to authorized roles only.
  • If a patch is not yet available, disable or remove the /callrec/audio.jsp endpoint from the exposed web surface until a fix is deployed.
  • Monitor application logs for anomalous requests to audio.jsp that contain suspicious characters or script payloads to detect attempted exploits.

Generated by OpenCVE AI on September 28, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Call Recording Software Play Audio audio.jsp cross site scripting
First Time appeared Eleveo
Eleveo call Recording Software
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo call Recording Software
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Call Recording Software
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T19:15:39.204Z

Reserved: 2026-09-28T08:11:17.439Z

Link: CVE-2026-101141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T20:17:08.490

Modified: 2026-09-28T21:03:44.987

Link: CVE-2026-101141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T22:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')