Local File Inclusion Vulnerability in Asseco SEE Live 2.0
CVE-2025-66955
6.5MEDIUM
What is CVE-2025-66955?
The Local File Inclusion vulnerability in Asseco SEE Live 2.0 affects the E-Mail, SMS, and Fax components, enabling remote authenticated users to access arbitrary files on the server. This issue arises from improper handling of the 'path' parameter in the downloadAttachment and downloadAttachmentFromPath API calls, potentially exposing sensitive information stored on the host. Proper permissions and input validation are crucial to mitigate the risks associated with this vulnerability.
