CVE-2025-66955
EUVD-2025-20861912.03.2026, 19:16
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| asseco | live | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration