Impact
The vulnerability resides in Eleveo Quality Management 9.7.0 and involves the Conversation Handler component. By manipulating the createdBy argument in the /enc-fwk-data/api/v3/conversations/<ID>/events endpoint, an attacker can cause the system to create or modify object attributes that are determined at runtime. This flaw allows remote actors to influence the internal data model, potentially leading to unauthorized data manipulation or configuration changes. The weakness is reflected in CWE‑913 and CWE‑915.
Affected Systems
Eleveo Quality Management, version 9.7.0, is the affected product. The problem is tied to the Conversation Handler component’s events API endpoint. No other versions or modules were identified as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 labels the issue as medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but public disclosure indicates the exploit has been published. Because the attack vector is remote and the endpoint is exposed over the web, the risk to organizations that expose the API to untrusted networks is significant. Exploitation requires only sending a crafted request with a modified createdBy parameter.
OpenCVE Enrichment