Cross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
Valid
Reported on
Sep 6th 2021
✍️ Description
Accept Bitcoin payments. Free, open-source & self-hosted, Bitcoin payment processor this package is vulnerable for xss
🕵️♂️ Proof of Concept
💥 Impact
This vulnerability is capable of stored XSS
Occurrences
We have contacted a member of the
btcpayserver
team and are waiting to hear back
2 years ago
Investigating on https://github.com/btcpayserver/btcpayserver/issues/2856
Fixed by https://github.com/btcpayserver/btcpayserver/pull/2863
to join this conversation