Impact
A flaw in the Eleveo Call Recording Software version 9.7.0 allows an attacker to manipulate the role argument in the /callrec/userAddAction.do endpoint, bypassing normal access controls and creating or modifying user accounts with unauthorized roles. This improper authorization can elevate privileges and compromise the integrity of the system. The weakness is identified by CWEs 266 and 285, indicating a deficit in permission checks and overall authorization logic.
Affected Systems
The vulnerability affects Eleveo Call Recording Software 9.7.0, specifically the /callrec/userAddAction.do endpoint. No other affected versions are listed in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. A public exploit is available and can be triggered remotely via HTTP to the vulnerable endpoint, enabling an attacker to gain elevated privileges without local access.
OpenCVE Enrichment