Impact
The vulnerability lies in Eleveo Quality Management 9.7.0, specifically the QuestionnaireService.runDataExportNow function. An attacker can manipulate the file_name argument to traverse the file system, allowing reading or writing of arbitrary files on the server. This opens the door for data leakage, tampering with configuration files, or potentially executing code if writable files such as scripts or executables can be replaced. The vulnerability is exploitable from a remote source and publicly available exploits exist. The impact is therefore a significant confidentiality and integrity risk, with the possibility of remote code execution as a secondary consequence.
Affected Systems
Version 9.7.0 of Eleveo Quality Management is affected. No other versions or products are listed for this issue.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack is described as remote and publicly available, meaning an attacker could trigger the path traversal over the network. Although the score is moderate, the ability to read or write arbitrary files could enable deeper compromise, making vigilance and early remediation important.
OpenCVE Enrichment