在 Eleveo 呼叫录音软件 9.7.0 中发现了一个漏洞。该漏洞影响组件“查询构建器”(Query Builder)中 文件的未知部分。此操纵会导致访问控制不当。攻击者可进行远程利用。该漏洞已被公开披露,可能被用于实际攻击。厂商在披露早期已收到通知,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eleveo | Call Recording Software | 9.7.0 |
cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101142 | 6.3 MEDIUM | Eleveo Quality Management Questionnaire Audio Upload Scorecard.jsp path traversal |
| CVE-2026-101143 | 4.3 MEDIUM | Eleveo Quality Management QMBODownload information disclosure |
| CVE-2026-101145 | 4.3 MEDIUM | Eleveo Call Recording Software User Management userAddAction.do ldap injection |
| CVE-2026-101146 | 4.3 MEDIUM | Eleveo Quality Management GWT RPC QMUtilsService UtilsService.createAndSaveAudit informati |
| CVE-2026-101141 | 3.5 LOW | Eleveo Call Recording Software Play Audio audio.jsp cross site scripting |
No comments yet