Description

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.

INFO

Published Date :

2026-03-12T00:00:00.000Z

Last Modified :

2026-03-14T03:32:45.511Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-66955 vulnerability.

Vendors Products
Asseco
  • See Live
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-66955.

CVSS Vulnerability Scoring System