CVE-2023-0493
published 2023-01-26CVE-2023-0493: Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
7.90%
94.0th percentile
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| btcpayserver | btcpay_server | < 1.7.5 | 1.7.5 |
| btcpayserver | btcpayserver_btcpayserver | >= unspecified < 1.7.5 | 1.7.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →HTML injection occurs in BTCPay Server when removing/deleting an API key — monitor for unexpected HTML tags in API key name fields submitted to the BTCPay Server application ↗
- →Affected version is BTCPay Server v1.7.4 and prior to 1.7.5; flag installations running these versions ↗
- ·Vulnerability is an Improper Neutralization of Equivalent Special Elements (HTML Injection), not a full XSS; impact may be limited to UI manipulation rather than script execution depending on context ↗
- ·Fix is available in BTCPay Server 1.7.5; any instance below this version should be considered vulnerable ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.htmlhttps://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039ahttps://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896fhttp://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.htmlhttps://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039ahttps://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896f
2023-01-26
Published