在 Eleveo Call Recording Software 9.7.0 中发现了缺陷。该缺陷影响的是文件 的未知部分。通过对参数 或 进行操纵,可引发跨站脚本(XSS)漏洞。该攻击可远程发起。利用方法已公开,可能被使用。厂商已就此披露事宜提前联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eleveo | Call Recording Software | 9.7.0 |
cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85408 | 4.3 MEDIUM | Eleveo Quality Management Conversation events dynamically-determined object attributes |
| CVE-2026-85407 | 4.3 MEDIUM | Eleveo Quality Management Conversation events denial of service |
| CVE-2026-85406 | 3.5 LOW | Eleveo Quality Management Conversation Review cross site scripting |
No comments yet