Executive brief
Eleveo Quality Management is a platform used to manage and review customer conversations and quality assurance workflows. The Conversation Review component contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject and execute malicious scripts in users' browsers, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in the Conversation Review component of Eleveo Quality Management version 9.7.0. The vulnerable code does not properly sanitize user-supplied input before rendering it in web responses, allowing an attacker to inject arbitrary JavaScript. Remote exploitation is possible without requiring authentication or user interaction beyond viewing a malicious link. Successful exploitation enables an attacker to execute arbitrary JavaScript in the context of a victim's session, potentially stealing session tokens or performing actions as that user. The vendor was contacted early but has not responded with a patch as of the advisory date.
Affected products
- Eleveo Quality Management 9.7.0
Timeline
- 2026-09-04: disclosed
- 2026-09-04: advisory