CVE-2021-3646: Cross-site Scripting (XSS) - Reflected in btcpayserver/btcpayserver
Published Sep 10, 2021
·Updated
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
btcpayserver Btcpay Server<1.2.3
Remediation
Event History
Sep 10, 2021
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-3646?
CVE-2021-3646 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2021-3646?
To mitigate CVE-2021-3646, you should update BTCPayServer to version 1.2.3 or later.
3
Who is affected by CVE-2021-3646?
CVE-2021-3646 affects all versions of BTCPayServer prior to 1.2.3.
4
What type of vulnerability is CVE-2021-3646?
CVE-2021-3646 is a cross-site scripting (XSS) vulnerability that allows for improper neutralization of input.
5
What can attackers do with CVE-2021-3646?
Attackers exploiting CVE-2021-3646 can potentially execute arbitrary scripts in the context of users' browsers.