CVE-2020-10800: Lix Project Lix

High severity, CVSS 8.1. EPSS: 1.4% chance of exploitation in the next 30 days.

lix through 15.8.7 allows man-in-the-middle attackers to execute arbitrary code by modifying the HTTP client-server data stream so that the Location header is associated with attacker-controlled executable content in the postDownload field.

Affected products

Published 2020-03-21. Last modified 2026-06-17.