← Back

CVE-2025-66955

nvd nist
Published: Mar 12, 2026Modified: Jul 5, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.

Affected (1)

Products: Asseco: Live
1 product
Live
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0

References (2)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Product

Timeline

No history available yet.