Sceawere

Vulnerability Detail

CVE-2026-85406UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Eleveo Quality Management XSS Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.5
Creation Date
3h ago
Vendor
Eleveo
Product
Quality Management
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.5",
  "pubDate": "2026-09-04T04:18:08.617Z",
  "pubdate": "2026-09-04T04:18:08.617Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability has been identified within the Conversation Review component of Eleveo Quality Management version 9.7.0.\nThis vulnerability allows an unauthenticated or remote attacker to inject malicious scripts into web pages viewed by other users within the application environment.\nSuccessful exploitation compromises the integrity and confidentiality of the user session, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive data.\nThe vulnerability is currently subject to public disclosure, increasing the risk of active exploitation by malicious actors.\nAs the vendor has remained unresponsive to disclosure efforts, no official security patches are currently available, necessitating immediate implementation of compensatory controls to mitigate exposure.",
  "technicalDetails": "The vulnerability resides within the Conversation Review component of Eleveo Quality Management 9.7.0, where improper input validation and output encoding mechanisms fail to sanitize user-supplied data before rendering it in the browser.\nThe root cause is an inadequate implementation of context-aware output encoding. When the application processes user-controlled input intended for the Conversation Review module, it fails to properly neutralize HTML tags, JavaScript event handlers, or other executable scripts. Consequently, the browser interprets this malicious payload as legitimate content, executing it within the security context of the affected user's session.\nThe attack flow typically involves the attacker crafting a malicious payload—such as a script designed to steal session cookies, capture keystrokes, or perform unauthorized administrative actions—and injecting this into a field or parameter handled by the Conversation Review interface. Once the target user navigates to the compromised section of the application, the payload is triggered automatically.\nBecause the vulnerability is remotely exploitable, attackers do not require physical access to the server. The lack of proper server-side filtering allows for the persistence of the malicious script (if stored) or immediate execution (if reflected).\nPost-exploitation, the impact is significant. An attacker could bypass existing session management controls, perform actions on behalf of the victim with the victim’s current privileges, or redirect the user to malicious external sites. Given that this is a Quality Management platform, the sensitivity of the data accessed during the session—such as communication logs, performance metrics, or customer interaction records—heightens the severity of the threat.\nThe vulnerability is confirmed in Eleveo Quality Management version 9.7.0. Given the public disclosure and lack of vendor response, the attack surface remains exposed, and administrators must treat the platform as inherently untrusted until input sanitization libraries are updated or proper output encoding is enforced globally across the application framework."
}
CVE-2026-85406: Eleveo Quality Management XSS Vulnerability (LOW Severity, CVSS: 3.5) - Sceawere