Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server.
History

Tue, 18 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Mar 2025 11:30:00 +0000

Type Values Removed Values Added
Description Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload files to the server via the ‘/softdial/phpconsole/upload.php’ endpoint, which is protected by basic HTTP authentication. The files are uploaded to a directory exposed by the web application, which could result in code execution, giving the attacker full control over the server.
Title Unrestricted file upload vulnerability in Softdial Contact Center
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-03-18T11:27:07.636Z

Updated: 2025-03-18T13:02:27.241Z

Reserved: 2025-03-18T09:23:43.896Z

Link: CVE-2025-2494

cve-icon Vulnrichment

Updated: 2025-03-18T13:02:24.291Z

cve-icon NVD

Status : Received

Published: 2025-03-18T12:15:16.090

Modified: 2025-03-18T12:15:16.090

Link: CVE-2025-2494

cve-icon Redhat

No data.