CVE-2026-101141: Eleveo Call Recording Software Play Audio audio.jsp cross site scripting
A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audio.jsp of the component Play Audio Page. Executing a manipulation of the argument viewRoleId/cfType can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access and user interaction are required for exploitation?
The attack can be launched remotely, but the attacker needs low privileges and user interaction is required. The vulnerable inputs are viewRoleId and cfType on the Play Audio page.
Which deployments are identified as affected?
The reported affected version is Eleveo Call Recording Software 9.7.0. The issue is associated with /callrec/audio.jsp in the Play Audio Page component.
How urgent is remediation given the available exploit information?
An exploit has been published and may be used. The vendor was contacted about the disclosure but did not respond.