Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2021-29247

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
Attacker Value
Unknown

CVE-2021-29246

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
Attacker Value
Unknown

CVE-2021-29245

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
Attacker Value
Unknown

CVE-2021-29248

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
Attacker Value
Unknown

CVE-2021-29250

Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.
Attacker Value
Unknown

CVE-2021-29251

Disclosure Date: April 01, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
Attacker Value
Unknown

CVE-2021-29249

Disclosure Date: March 26, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.