Description
A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure via Path Traversal
Action: Apply Patch
AI Analysis

Impact

A path traversal flaw exists in the Scorecard.jsp component of Eleveo Quality Management, allowing a remote attacker to read arbitrary files on the host. The flaw can expose sensitive data and may assist in further intrusion attempts. The vulnerability was discovered in version 9.7.0.

Affected Systems

Eleveo Quality Management 9.7.0 is affected. No other versions are listed as vulnerable in the available data.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity. No EPSS value is reported, so the exploitation probability is unknown. The vulnerability is not included in the CISA KEV catalog. An attacker can trigger the flaw by sending a crafted HTTP request to the Scorecard.jsp endpoint, including directory traversal sequences in parameters. Because the vendor has not released a patch, the risk persists until an update is applied.

Generated by OpenCVE AI on September 28, 2026 at 20:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Eleveo Quality Management to a version that contains a fix for the path traversal issue.
  • Configure the web server to enforce strict path validation for requests to Scorecard.jsp, rejecting any traversal sequences.
  • Implement input sanitization on the Scorecard.jsp parameters to strip or neutralize '../' and other traversal characters.
  • Limit external network access to the Scorecard.jsp endpoint using firewall rules or IP whitelisting.

Generated by OpenCVE AI on September 28, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal
First Time appeared Eleveo
Eleveo quality Management
Weaknesses CWE-22
CPEs cpe:2.3:a:eleveo:quality_management:*:*:*:*:*:*:*:*
Vendors & Products Eleveo
Eleveo quality Management
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Eleveo Quality Management
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T19:30:11.384Z

Reserved: 2026-09-28T08:11:21.155Z

Link: CVE-2026-101142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T20:17:08.687

Modified: 2026-09-28T20:17:08.687

Link: CVE-2026-101142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T20:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')