Executive brief
Eleveo Quality Management is a quality assurance and survey platform used by organizations to manage questionnaires and gather feedback. A path traversal vulnerability in the data export function allows a remote attacker to read or manipulate files on the affected system, potentially exposing sensitive data or enabling system compromise.
Technical details
A path traversal vulnerability exists in the QuestionnaireService.runDataExportNow function in Eleveo Quality Management 9.7.0, where the file_name parameter is not properly validated. An unauthenticated remote attacker can inject path traversal sequences (e.g., ../) to access or export arbitrary files outside the intended directory. The vulnerability is remotely exploitable without authentication, and a proof-of-concept exploit is publicly available. No vendor patch has been released as the vendor has not responded to disclosure attempts.
Affected products
- Eleveo Quality Management 9.7.0
Timeline
- 2026-09-04: disclosed
- other: Exploit is publicly available