CVE-2026-101143: Eleveo Quality Management QMBODownload information disclosure
A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue can be launched remotely and requires low privileges. No user interaction is required.
Is there public exploit information available?
Yes. The exploit has been made public and could be used.
What version is known to be affected?
Eleveo Quality Management version 9.7.0 is identified as affected.
Has the vendor provided a response or remediation?
The vendor was contacted early about the disclosure but did not respond. No vendor fix or workaround is provided in the available information.