Impact
The description indicates that Eleveo Call Recording Software 9.7.0 contains a flaw in the /callrec/statisticReportAction.do endpoint that allows remote actors to manipulate requests and bypass authentication checks. This improper authorization is characterized by CWE-266 and CWE-285, enabling attackers to access data or functions that should be restricted. The vulnerability can be exploited remotely without local or privileged execution on the target system.
Affected Systems
The affected product is Eleveo Call Recording Software version 9.7.0. The vulnerability resides specifically in the statisticReportAction.do function of the /callrec package and does not appear to affect other versions or components based on the available information.
Risk and Exploitability
With a CVSS score of 5.3, the risk is classified as medium severity. An EPSS score of < 1% indicates a very low probability of exploitation, but the publicly disclosed exploit demonstrates that the vulnerability can be used in practice. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the attack means that the exposed endpoint remains reachable for malicious actors until a patch or mitigation is applied. This limited exploitation likelihood does not negate the potential for unauthorized data access, confidentiality violations, or integrity tampering if the endpoint is reached by an attacker.
OpenCVE Enrichment