CVE-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.
Configurations

No configuration.

History

16 Mar 2026, 14:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

13 Mar 2026, 19:53

Type Values Removed Values Added
References
  • {'url': 'http://live.com', 'source': 'cve@mitre.org'}
  • () https://live.asee.io/ -
Summary
  • (es) Inclusión local de ficheros en los componentes Contact Plan, E-Mail, SMS y Fax en Asseco SEE Live 2.0 permite a usuarios autenticados remotos acceder a ficheros en el host a través del parámetro 'path' en las llamadas a la API downloadAttachment y downloadAttachmentFromPath.

12 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 19:16

Updated : 2026-03-16 14:18


NVD link : CVE-2025-66955

Mitre link : CVE-2025-66955

CVE.ORG link : CVE-2025-66955


JSON object : View

Products Affected

No product.

CWE

No CWE.