VulnerabilityModified
CVE-2021-29246
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution.
MEDIUM 6.7EPSS 1.55%
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- btcpayserver/btcpay server
- Source
- cve@mitre.org
References
- https://blog.btcpayserver.org/vulnerability-disclosure-v1-0-7-0/Vendor Advisory
- https://github.com/btcpayserver/btcpayserver/releasesRelease Notes, Third Party Advisory
- https://blog.btcpayserver.org/vulnerability-disclosure-v1-0-7-0/Vendor Advisory
- https://github.com/btcpayserver/btcpayserver/releasesRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.