CVE-2020-13229: Sysax Multi Server

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An issue was discovered in Sysax Multi Server 6.90. A session can be hijacked if one observes the sid value in any /scgi URI, because it is an authentication token.

Affected products

  • Sysax Multi Server: version 6.90 only

Published 2020-06-02. Last modified 2026-06-17.