Executive brief
Eleveo Quality Management is a call center quality assurance platform. A vulnerability in the conversation event API allows an attacker to manipulate object attributes through the createdBy parameter, potentially leading to unauthorized data modification or exposure without requiring authentication.
Technical details
The vulnerability is a dynamically-determined object attribute injection flaw in the Conversation Handler component, specifically in the /enc-fwk-data/api/v3/conversations/{ID}/events endpoint. An attacker can craft a request with a malicious createdBy parameter to inject or modify object attributes. The vulnerability is remotely exploitable and does not require authentication. An attacker can manipulate conversation event metadata and potentially access or modify sensitive quality management data. The vendor has not provided a patch despite early notification.
Affected products
- Eleveo Quality Management 9.7.0
Timeline
- 2026-09-04: disclosed: Publicly disclosed vulnerability