Impact
A path traversal flaw exists in the Scorecard.jsp component of Eleveo Quality Management, allowing a remote attacker to read arbitrary files on the host. The flaw can expose sensitive data and may assist in further intrusion attempts. The vulnerability was discovered in version 9.7.0.
Affected Systems
Eleveo Quality Management 9.7.0 is affected. No other versions are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. No EPSS value is reported, so the exploitation probability is unknown. The vulnerability is not included in the CISA KEV catalog. An attacker can trigger the flaw by sending a crafted HTTP request to the Scorecard.jsp endpoint, including directory traversal sequences in parameters. Because the vendor has not released a patch, the risk persists until an update is applied.
OpenCVE Enrichment