Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-7570 | Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server. |
Tue, 21 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sytel
Sytel softdial Contact Center |
|
| CPEs | cpe:2.3:a:sytel:softdial_contact_center:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Sytel
Sytel softdial Contact Center |
|
| Metrics |
cvssV3_1
|
Tue, 18 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Mar 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server. | |
| Title | Unrestricted file upload vulnerability in Softdial Contact Center | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-18T13:02:27.241Z
Reserved: 2025-03-18T09:23:43.896Z
Link: CVE-2025-2494
Updated: 2025-03-18T13:02:24.291Z
Status : Analyzed
Published: 2025-03-18T12:15:16.090
Modified: 2025-10-21T14:48:39.507
Link: CVE-2025-2494
No data.
OpenCVE Enrichment
No data.
EUVD