Junglewise Threat Intelligence

CVE-2025-66955: Asseco SEE Live 2.0 Local File Inclusion in communication components

CVE-2025-66955 · Severity: medium · CVSS 6.5 · Published 2026-03-12

Executive brief

Asseco SEE Live 2.0, a platform used by banks and utilities for managing customer interactions and contact centers, contains a security vulnerability in its communication components. An authorized user can exploit this flaw to access sensitive system files on the server that should normally be protected. This could lead to the exposure of configuration data or other internal information, potentially compromising the security of the entire platform.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Contact Plan, E-Mail, SMS, and Fax components of Asseco SEE Live 2.0. The flaw is rooted in the improper validation of the 'path' parameter within the 'downloadAttachment' and 'downloadAttachmentFromPath' API calls. A remote attacker with low-level authentication can provide manipulated file paths (e.g., /etc/passwd) to the 'path' parameter via a POST request to /live20/index.php. Successful exploitation allows the attacker to read sensitive files from the underlying host operating system. While the reported CVSS is 6.5, some third-party assessments suggest a higher severity due to the potential for broad information disclosure.

Affected products

  • Asseco SEE Live 2.0 2.0

Timeline

  • 2026-03-12: advisory: Initial disclosure of CVE-2025-66955

References

Related threats