Impact
The Eleveo Call Recording Software 9.7.0 includes a flaw in the /callrec/group.jsp handler that fails to perform proper authorization checks. By manipulating requests to this endpoint, an attacker may be able to perform group‑management operations such as creating, viewing, or deleting group records. This could expose or alter metadata related to call recordings, potentially compromising the confidentiality and integrity of business communications. (Inference: The CVE description does not state that the attacker can create, view, or delete groups; this deduction is inferred from the fact that the endpoint is grouped under group management functions.)
Affected Systems
The vulnerability affects Eleveo Call Recording Software version 9.7.0. Only this release is reported by the vendor. Deployments that expose the /callrec/group.jsp endpoint to a network are at risk. No other versions or variants have been identified as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only network access to the web application. Without an official fix, the risk remains moderate, as unauthorized manipulation of group data could expose sensitive recordings.
OpenCVE Enrichment