Description
A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 28 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Eleveo Call Recording Software User Management userAddAction.do ldap injection | |
| First Time appeared |
Eleveo
Eleveo call Recording Software |
|
| Weaknesses | CWE-74 CWE-90 |
|
| CPEs | cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eleveo
Eleveo call Recording Software |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-28T20:15:09.632Z
Reserved: 2026-09-28T08:11:31.271Z
Link: CVE-2026-101145
No data.
No data.
No data.
OpenCVE Enrichment
No data.