CVE-2025-2493: Sytel Softdial Contact Center

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘/softdial/scheduler/load.php’ endpoint to navigate beyond the intended directory. This can allow unauthorised access to sensitive files outside the expected scope, posing a security risk.

Affected products

  • Sytel Softdial Contact Center: affected versions not specified

Published 2025-03-18. Last modified 2026-06-17.