在 Eleveo Call Recording Software 9.7.0 版本中发现了一个安全漏洞。该漏洞影响名为“Play Audio Page”(播放音频页面)组件中的 文件的一个未知函数。通过构造特定的 参数,攻击者可触发跨站脚本攻击(XSS)。此漏洞支持远程利用,且相关利用代码已公开,可能被恶意利用。尽管厂商在披露初期即收到通知,但至今未作出任何回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eleveo | Call Recording Software | 9.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eleveo | Call Recording Software | 9.7.0 |
cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101142 | 6.3 MEDIUM | Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal |
| CVE-2026-101144 | 6.3 MEDIUM | Eleveo Call Recording Software Query Builder searchAction.do access control |
| CVE-2026-101143 | 4.3 MEDIUM | Eleveo Quality Management QMBODownload information disclosure |
| CVE-2026-101145 | 4.3 MEDIUM | Eleveo Call Recording Software User Management userAddAction.do ldap injection |
| CVE-2026-101146 | 4.3 MEDIUM | Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit informati |
No comments yet