CVE-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:asseco:live:2.0:*:*:*:*:*:*:*

History

02 Jun 2026, 19:07

Type Values Removed Values Added
References () http://asseco.com - () http://asseco.com - Product
References () https://github.com/TheWoodenBench/CVE-2025-66955 - () https://github.com/TheWoodenBench/CVE-2025-66955 - Third Party Advisory
References () https://live.asee.io/ - () https://live.asee.io/ - Product
CPE cpe:2.3:a:asseco:live:2.0:*:*:*:*:*:*:*
First Time Asseco
Asseco live

12 May 2026, 01:16

Type Values Removed Values Added
CWE CWE-552

16 Mar 2026, 14:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Mar 2026, 19:53

Type Values Removed Values Added
References
  • {'url': 'http://live.com', 'source': 'cve@mitre.org'}
  • () https://live.asee.io/ -
Summary
  • (es) Inclusión local de ficheros en los componentes Contact Plan, E-Mail, SMS y Fax en Asseco SEE Live 2.0 permite a usuarios autenticados remotos acceder a ficheros en el host a través del parámetro 'path' en las llamadas a la API downloadAttachment y downloadAttachmentFromPath.

12 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 19:16

Updated : 2026-06-02 19:07


NVD link : CVE-2025-66955

Mitre link : CVE-2025-66955

CVE.ORG link : CVE-2025-66955


JSON object : View

Products Affected

asseco

  • live
CWE
CWE-552

Files or Directories Accessible to External Parties