A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Sun, 12 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This issue affects some unknown processing of the file /callrec/restoreCallAction.do of the component Recorded Calls Page. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization | |
| First Time appeared |
Eleveo
Eleveo call Recording Software |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:eleveo:call_recording_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eleveo
Eleveo call Recording Software |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-07-12T01:30:08.975Z
Updated: 2026-07-14T14:34:01.039Z
Reserved: 2026-07-11T09:33:25.486Z
Link: CVE-2026-15473
Updated: 2026-07-14T14:33:55.097Z
No data.
No data.