CVE-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.
References
Link Resource
https://github.com/TheWoodenBench/CVE-2025-66955 Third Party Advisory
https://live.asee.io/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:asseco:live:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-12 19:16

Updated : 2026-07-05 02:17


NVD link : CVE-2025-66955

Mitre link : CVE-2025-66955

CVE.ORG link : CVE-2025-66955


JSON object : View

Products Affected

asseco

  • live
CWE
CWE-552

Files or Directories Accessible to External Parties