Impact
A flaw in Eleveo Call Recording Software 9.7.0’s users_ldap.jsp allows attackers to manipulate requests and bypass authorization checks, potentially granting unintended access to LDAP resources; the weakness stems from insufficient privilege controls (CWE‑266) and improper authorization (CWE‑285). Successful exploitation could let an attacker view or modify LDAP entries, undermining confidentiality and integrity.
Affected Systems
The vulnerability exists in Eleveo Call Recording Software version 9.7.0. The affected component is the LDAP User Interface, specifically the users_ldap.jsp resource, which is part of the standard installation and not limited to any particular deployment scenario.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack can be initiated remotely by sending crafted requests to the LDAP User Interface; no special conditions are described, so based on the description it is inferred that any system exposing the interface to untrusted networks may be at risk.
OpenCVE Enrichment