CVE-2025-2494

Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sytel:softdial_contact_center:-:*:*:*:*:*:*:*

History

21 Oct 2025, 14:48

Type Values Removed Values Added
Summary
  • (es) Subida de archivos sin restricciones al Centro de Contacto Softdial de Sytel Ltd. Esta vulnerabilidad podría permitir a un atacante subir archivos al servidor a través del endpoint '/softdial/phpconsole/upload.php', protegido por autenticación HTTP básica. Los archivos se suben a un directorio expuesto por la aplicación web, lo que podría provocar la ejecución de código, otorgando al atacante control total sobre el servidor.
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-softdial-contact-center - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-softdial-contact-center - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Sytel
Sytel softdial Contact Center
CPE cpe:2.3:a:sytel:softdial_contact_center:-:*:*:*:*:*:*:*

18 Mar 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-18 12:15

Updated : 2025-10-21 14:48


NVD link : CVE-2025-2494

Mitre link : CVE-2025-2494

CVE.ORG link : CVE-2025-2494


JSON object : View

Products Affected

sytel

  • softdial_contact_center
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type