Impact
A flaw exists in Eleveo Call Recording Software 9.7.0 that allows a remote attacker to manipulate the /callrec/roleAddAction.do endpoint. This leads to improper authorization, enabling unauthorized users to gain access to the Group Interface. The vulnerability originates from an unknown function within that component, and the exploit is publicly available.
Affected Systems
The software vendor Eleveo produces the Call Recording Software, specifically version 9.7.0. Systems running this version are directly affected; no other versions were listed in the provided CVE data.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate range, yet the attack vector is remote and the exploit has already been published, indicating that attackers can launch the attack without needing local privileges. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog. The risk remains significant because the flaw directly impacts authorization controls and could allow unauthorized actions within the application.
OpenCVE Enrichment