Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion via downloadAttachment Path Parameter in Asseco SEE Live 2.0 |
Tue, 12 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in API Download Endpoints Allows Remote Authenticated Users to Read Host Files | |
| Weaknesses | CWE-200 CWE-22 |
Tue, 12 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-552 |
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in API Download Endpoints Allows Remote Authenticated Users to Read Host Files | |
| Weaknesses | CWE-200 CWE-22 |
Fri, 27 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LFI in Asseco SEE Live 2.0 Exposes Arbitrary Files to Authenticated Users | |
| Weaknesses | CWE-20 CWE-22 |
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LFI in Asseco SEE Live 2.0 Exposes Arbitrary Files to Authenticated Users | |
| Weaknesses | CWE-20 CWE-22 |
Thu, 26 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated File Disclosure via API Path Parameter | |
| Weaknesses | CWE-22 |
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated File Disclosure via API Path Parameter | |
| Weaknesses | CWE-22 |
Wed, 25 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in Asseco SEE Live 2.0 Allows Remote Authenticated Users to Read Arbitrary Files | |
| Weaknesses | CWE-200 CWE-22 |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in Asseco SEE Live 2.0 Allows Remote Authenticated Users to Read Arbitrary Files | |
| Weaknesses | CWE-200 CWE-22 |
Tue, 24 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Authenticated File Disclosure via Path Parameter in Asseco SEE Live 2.0 | |
| Weaknesses | CWE-22 |
Mon, 23 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Authenticated File Disclosure via Path Parameter in Asseco SEE Live 2.0 | |
| Weaknesses | CWE-22 |
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in Asseco SEE Live 2.0 Allows Authenticated Users to Read Arbitrary Host Files | |
| Weaknesses | CWE-200 CWE-22 |
Fri, 20 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in Asseco SEE Live 2.0 Allows Authenticated Users to Read Arbitrary Host Files | |
| Weaknesses | CWE-200 CWE-22 |
Sat, 14 Mar 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 13 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 13 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 13 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Asseco
Asseco see Live |
|
| Vendors & Products |
Asseco
Asseco see Live |
Thu, 12 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-12T00:05:49.349Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-66955
Updated: 2026-03-14T03:32:28.009Z
Status : Awaiting Analysis
Published: 2026-03-12T19:16:15.077
Modified: 2026-05-12T01:16:45.750
Link: CVE-2025-66955
No data.
OpenCVE Enrichment
Updated: 2026-05-12T04:30:07Z