Vulnerabilities
Vulnerable Software
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.8.0.
CVSS Score
5.7
EPSS Score
0.001
Published
2023-03-02
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-02-17
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
CVSS Score
7.5
EPSS Score
0.004
Published
2023-01-31
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
CVSS Score
5.3
EPSS Score
0.011
Published
2023-01-26


Contact Us

Shodan ® - All rights reserved