Impact
This vulnerability is an instance of uncontrolled script injection via the name/username field in the /callrec/roleAddAction.do endpoint. Altering that argument causes the software to render malicious JavaScript in the browser of any user who views the affected response. The flaw can lead to session hijacking, defacement, or further web-based attacks, compromising confidentiality and integrity of user data.
Affected Systems
Eleveo Call Recording Software version 9.7.0 is explicitly affected. No other versions are listed, so only installations of 9.7.0 or earlier that have not been patched should be considered vulnerable.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate impact and the EPSS data is unavailable, yet the exploit has been published and is documented as usable. The absence from the KEV catalog does not negate the risk. Attackers can trigger the flaw remotely by sending a crafted HTTP request to the vulnerable endpoint, exploiting the XSS to steal session cookies or inject further payloads.
OpenCVE Enrichment