CVE-2025-2494
Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server.
Vendor
Product
CWE
Yayın Tarihi
2025-03-18 12:15:16
Güncelleme
2025-10-21 14:48:39
Source Identifier
cve-coordination@incibe.es
KEV Date Added
-