Description
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
References
https://blog.btcpayserver.org/btcpay-server-cve-2022-32984/
Vendor Advisory
https://blog.btcpayserver.org/btcpay-server-cve-2022-32984/
Vendor Advisory
Weaknesses
Primary
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-200
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
7.5 · High
Information
Source identifier
Vulnerability status
Modified
Published
2023-01-31T21:15:08.000Z
3 years agoLast modified
2025-03-27T18:15:44.950Z
1 year ago