Impact
Eleveo Call Recording Software 9.7.0 contains a flaw in its pci_dss_status.jsp page that allows an attacker to bypass the built-in authorization checks. This improper handling of user credentials and permissions (CWE-266 and CWE-285) can give a remote adversary unauthenticated read or modification of sensitive PCI DSS status information.
Affected Systems
It affects Eleveo Call Recording Software version 9.7.0. No other product versions or components are listed as vulnerable, and the flaw is located in the /callrec/pci_dss_status.jsp component of this particular release.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a low overall exploitation probability, yet the exploit has been made publicly available, which represents a real threat.
OpenCVE Enrichment