Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Link | Tags |
---|---|
https://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896f | exploit third party advisory patch |
https://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039a | patch |
http://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.html | vdb entry third party advisory |