Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2021-29247
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the HTTPOnly flag for a cookie.
0
Attacker Value
Unknown
CVE-2021-29246
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
0
Attacker Value
Unknown
CVE-2021-29245
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
0
Attacker Value
Unknown
CVE-2021-29248
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set the Secure flag for a cookie.
0
Attacker Value
Unknown
CVE-2021-29250
Disclosure Date: May 05, 2021 (last updated February 22, 2025)
BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products functionality. This enables cookie stealing.
0
Attacker Value
Unknown
CVE-2021-29251
Disclosure Date: April 01, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). This affects Docker use cases in which a mail server is configured.
0
Attacker Value
Unknown
CVE-2021-29249
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
0