CVE-2025-66955: Asseco Live
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls.
Affected products
- Asseco Live: version 2.0 only
Published 2026-03-12. Last modified 2026-07-05.