Description
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15885 | BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T22:02:51.544Z
Reserved: 2021-03-26T00:00:00.000Z
Link: CVE-2021-29246
No data.
Status : Modified
Published: 2021-05-05T13:15:07.650
Modified: 2024-11-21T06:00:52.507
Link: CVE-2021-29246
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD