Junglewise Threat Intelligence

CVE-2025-2154: Echo Call Center Services Specto CM stored XSS

CVE-2025-2154 · Severity: medium · CVSS 5.4 · Published 2025-12-24

Executive brief

Specto CM, a call center management platform, is affected by a security vulnerability that allows attackers to inject malicious scripts into the system. If an employee or administrator views the affected area, the attacker could potentially steal session information or perform unauthorized actions on their behalf. This could lead to unauthorized access to customer data or disruption of call center operations.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Echo Call Center Services Specto CM prior to version 17032025. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An authenticated attacker with low privileges can inject malicious JavaScript into persistent data fields. When other users, such as administrators, view the compromised data, the script executes in their browser session. This can lead to session hijacking, unauthorized data modification, or further privilege escalation within the application.

Affected products

  • Echo Call Center Services Trade and Industry Inc. Specto CM before 17032025

Timeline

  • 2025-12-24: disclosed
  • 2025-12-24: advisory

References

Related threats