BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-01-31T00:00:00

Updated: 2024-08-03T07:54:03.456Z

Reserved: 2022-06-10T00:00:00

Link: CVE-2022-32984

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-01-31T22:15:08.000

Modified: 2023-02-08T22:22:38.523

Link: CVE-2022-32984

cve-icon Redhat

No data.