CVE-2020-26885: 2sic 2sxc

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was discovered in 2sic 2sxc before 11.22. A XSS vulnerability in the sxcver parameter of dnn/ui.html allows an attacker to craft a malicious URL that executes a JavaScript payload in a victim's browser.

Affected products

  • 2sic 2sxc: from 8.00.00, before 11.22.00 (fixed in 11.22.00)

Published 2021-06-07. Last modified 2026-06-17.