CVE-2020-26799: XSS
Published Jul 21, 2025
·Updated
A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.
Affected Software
1 affected component
Luxcal Luxcal
Event History
Jul 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-26799?
CVE-2020-26799 has a medium severity rating as it can allow an unauthenticated attacker to execute malicious scripts.
2
How do I fix CVE-2020-26799?
To fix CVE-2020-26799, update Luxcal to the latest version that addresses this vulnerability.
3
What kind of vulnerability is CVE-2020-26799?
CVE-2020-26799 is a reflected cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2020-26799?
Unauthenticated users of Luxcal 4.5.2 are at risk of CVE-2020-26799, as attackers can exploit this vulnerability to steal user data.
5
What are the potential impacts of CVE-2020-26799?
The potential impacts of CVE-2020-26799 include unauthorized access to sensitive user information and the possibility of session hijacking.