Impact
The vulnerability allows an attacker to manipulate the /callrec/composeEmailAction.do endpoint in Eleveo Call Recording Software version 9.7.0, resulting in improper authorization. This flaw is listed as CWE-266 and CWE-285, indicating failures in enforcing authentication and authorization checks. An attacker who can send crafted requests to this endpoint can invoke actions normally restricted to privileged users, potentially accessing or sending recordings via the email composition feature.
Affected Systems
Eleveo Call Recording Software version 9.7.0 is affected. No other versions have been explicitly reported as vulnerable. The vendor's product is listed as Eleveo:Call Recording Software.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. Because the flaw can be triggered remotely through HTTP requests to the composeEmailAction.do endpoint, it remains publicly exploitable. As it is not listed in the CISA KEV catalog, there have been no public reports of widespread usage, but the lack of a vendor fix means it continues to pose a risk to installations that allow the endpoint to be reached from untrusted networks.
OpenCVE Enrichment