Impact
The vulnerability arises from improper access controls within the Query Builder component of Eleveo Call Recording Software. This flaw allows an attacker to manipulate requests to /callrec/searchAction.do and gain unauthorized access or elevate privileges, leading to potential data exposure or unauthorized configuration changes. The weakness is identified as a privilege escalation (CWE-266) and general improper access control (CWE-284).
Affected Systems
Eleveo Call Recording Software version 9.7.0 is affected by this issue. The vulnerability resides in the /callrec/searchAction.do file of the Query Builder component, which is deployed on systems running that specific version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. Exploitation is feasible over the network, as the web application component can be accessed remotely. Although EPSS information is not available and the vulnerability is not listed in CISA KEV, the public disclosure of exploit code suggests that attackers could potentially leverage this flaw to bypass authentication and gain unauthorized access. The lack of a vendor patch requires mitigations to be applied by system administrators.
OpenCVE Enrichment