Impact
The vulnerability in Eleveo Call Recording Software version 9.7.0 allows remote attackers to exploit the /callrec/restoreCallAction.do endpoint and bypass the application’s authorization checks. By manipulating requests to this endpoint, an attacker can restore or view call recordings without proper permission, exposing confidential audio data and compromising the privacy of users. This flaw corresponds to CWE-266 (Improper Privilege Assignment) and CWE-285 (Improper Authorization).
Affected Systems
Eleveo Call Recording Software, version 9.7.0, is affected by this authorization flaw. No other versions were identified as vulnerable in the available information.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while an EPSS score of less than 1% suggests that the likelihood of exploitation is currently low. Nonetheless, the attack is possible to be carried out remotely and the exploit code is publicly available. The vulnerability is not listed in CISA’s KEV catalog. The overall risk remains moderate, and organizations should treat it as a potential threat to confidentiality and integrity of recorded data.
OpenCVE Enrichment