CVE-2023-0493 EXPLOIT
5.3
MEDIUM · CVSS 3.1 · EPSS 7.9% (pctl 95)
Patch early
A public exploit exists.
Description
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Scoring
| CVSS | 5.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 7.9% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-76 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-01-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| btcpayserver | btcpay server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | BTCPay Server v1.7.4 - HTML Injection | 2023-04-05 |
References
- http://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.html
- https://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039a
- https://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896f
- http://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.html
- https://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039a
- https://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896f
→ the Explorer · watch your stack · NVD