Impact
A flaw exists in the Conversation Review component of Eleveo Quality Management 9.7.0 that allows an attacker to inject arbitrary script payloads into the web page rendered for legitimate users. The vulnerability is triggered by manipulating unknown code within that component, enabling the execution of malicious JavaScript in the victim’s browser. Attacks can occur remotely via specially crafted requests, and the resulting XSS can lead to session hijacking, credential theft, or the execution of other malicious actions in the context of authenticated users.
Affected Systems
Eleveo Quality Management version 9.7.0. The vulnerability is specific to the Conversation Review feature of that product.
Risk and Exploitability
The CVSS score of 5.1 classifies the flaw as a moderate risk, and while an EPSS score is unavailable, the exploit is described as publicly disclosed and remotely exploitable. The flaw is not yet listed in the CISA KEV catalog, so it may not be widely targeted yet. Because it is an XSS issue (CWE‑79) involving script injection, any user who can trigger the Conversation Review code and view the content is at risk. The likely attack vector is a web‑based request that reaches the vulnerable code and returns a page containing the injected script.
OpenCVE Enrichment