vendor:
BTCPayServer
by:
Manojkumar J (TheWhiteEvil)
8.8
CVSS
HIGH
HTML Injection
79
CWE
Product Name: BTCPayServer
Affected Version From: <=1.7.4
Affected Version To: <=1.7.4
Patch Exists: YES
Related CWE: CVE-2023-0493
CPE: a:btcpayserver:btcpayserver:1.7.4
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=78149, https://www.infosecmatter.com/nessus-plugin-library/?id=83872, https://www.infosecmatter.com/nessus-plugin-library/?id=25297, https://www.infosecmatter.com/nessus-plugin-library/?id=57606, https://www.infosecmatter.com/nessus-plugin-library/?id=74623, https://www.infosecmatter.com/nessus-plugin-library/?id=141848, https://www.infosecmatter.com/nessus-plugin-library/?id=13653, https://www.infosecmatter.com/nessus-plugin-library/?id=79613, https://www.infosecmatter.com/nessus-plugin-library/?id=148267, https://www.infosecmatter.com/nessus-plugin-library/?id=56565
Platforms Tested: Windows10
2023
BTCPay Server v1.7.4 – HTML Injection
BTCPay Server v1.7.4 HTML injection vulnerability. An attacker can inject malicious HTML code into the label field of the API key, which will be rendered when the API key is deleted.
Mitigation:
Input validation should be used to prevent malicious HTML code from being injected.