Local File Inclusion Vulnerability in Asseco SEE Live 2.0
CVE-2025-66955

6.5MEDIUM

Key Information:

Vendor

Asseco SEE

Vendor
CVE Published:
12 March 2026

What is CVE-2025-66955?

The Local File Inclusion vulnerability in Asseco SEE Live 2.0 affects the E-Mail, SMS, and Fax components, enabling remote authenticated users to access arbitrary files on the server. This issue arises from improper handling of the 'path' parameter in the downloadAttachment and downloadAttachmentFromPath API calls, potentially exposing sensitive information stored on the host. Proper permissions and input validation are crucial to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.