Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33gv-rvgq-gpxp

Опубликовано: 27 янв. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Withdrawn Advisory: HTML injections in BTCPayServer

Withdrawn Advisory

This advisory has been withdrawn because all of the files affected by this vulnerability lie in the BTCPayServer folder, which is not in the NuGet ecosystem. The BTCPayServer folder, corresponding to the BTCPayServer NuGet entry, does not contain any files that were changed to fix the vulnerability.

Original Description

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

Пакеты

Наименование

BTCPayServer.Client

nuget
Затронутые версииВерсия исправления

< 1.7.5

1.7.5

EPSS

Процентиль: 80%
0.01362
Низкий

8.8 High

CVSS3

Дефекты

CWE-74
CWE-76

Связанные уязвимости

CVSS3: 5.3
nvd
около 3 лет назад

Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.

EPSS

Процентиль: 80%
0.01362
Низкий

8.8 High

CVSS3

Дефекты

CWE-74
CWE-76