CVE-2026-101145 | Eleveo Call Recording Software 9.7.0 User Management userAddAction.do Username ldap injection

SecurityVulns

A vulnerability described as problematic has been identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the file /callrec/userAddAction.do of the component User Management. Such manipulation of the argument Username leads to ldap injection.

This vulnerability is documented as CVE-2026-101145. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More