CVE-2026-101141
Deferred Deferred - Pending Action

Cross-Site Scripting in Eleveo Call Recording Software

Vulnerability report for CVE-2026-101141, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
eleveo call_recording_software 9.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in Eleveo Call Recording Software version 9.7.0. It exists in the Play Audio Page component, specifically in the file /callrec/audio.jsp. The issue arises from improper handling of the viewRoleId and cfType arguments, allowing attackers to inject malicious scripts. The exploit is publicly available and can be launched remotely.

Detection Guidance

To detect this XSS vulnerability in Eleveo Call Recording Software 9.7.0, inspect web server logs for requests to /callrec/audio.jsp with parameters viewRoleId or cfType. Look for unusual input patterns like script tags or JavaScript events in these parameters.

Impact Analysis

This XSS vulnerability could allow attackers to execute malicious scripts in a user's browser when they access the affected page. This may lead to theft of session cookies, account hijacking, or defacement of the application. Users with access to the call recording system could be targeted, potentially exposing sensitive audio data or other confidential information.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by potentially exposing sensitive personal or health-related audio data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A successful XSS attack could lead to unauthorized access, violating these regulations and resulting in legal penalties or reputational damage.

Mitigation Strategies

Immediately update Eleveo Call Recording Software to the latest version if available. If no patch exists, restrict access to /callrec/audio.jsp via web server rules. Implement input validation for viewRoleId and cfType parameters to block script tags and special characters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101141. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart