CVE-2020-10800

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2020
Last modified:
21/07/2021

Description

lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lix_project:lix:*:*:*:*:*:*:*:* 15.8.7 (including)


References to Advisories, Solutions, and Tools