Impact
Eleveo Quality Management version 9.7.0 contains a flaw in the QMBODownload functionality that allows remote attackers to manipulate the /qm/cz.zoom.scorecard.webui.Scorecard path and retrieve sensitive data. The vulnerability results in a breach of confidentiality, exposing potentially privileged scorecard information to unauthenticated parties. Because the exploit deals with unauthenticated download functionality, an attacker can gain this information by simply forming a request to the vulnerable endpoint.
Affected Systems
The affected product is Eleveo Quality Management, specifically version 9.7.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available but the public disclosure and availability of an exploit indicate that the vulnerability may be actively abused. The vulnerability is not yet listed in the CISA KEV catalog, suggesting that it has not yet been widely recognized as a serious threat by federal agencies. Attackers are likely to target the exposed download path remotely, using crafted requests to extract data without authentication. Given the lack of a vendor response, the risk remains present as long as the vulnerable instance remains exposed.
OpenCVE Enrichment