CVE-2021-3830: Cross-site Scripting (XSS) - Stored in btcpayserver/btcpayserver
Published Sep 26, 2021
·Updated
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected Software
1 affected component
btcpayserver Btcpay Server<=1.2.3
Remediation
Event History
Sep 26, 2021
CVE Published
via MITRE·08:15 AM
Data Sourced
via MITRE·08:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-3830.
2
What is the severity of CVE-2021-3830?
The severity of CVE-2021-3830 is medium with a CVSS score of 5.4.
3
What is the affected software of CVE-2021-3830?
The affected software of CVE-2021-3830 is btcpayserver version 1.2.3.
4
What is the vulnerability type of CVE-2021-3830?
The vulnerability type of CVE-2021-3830 is 'Improper Neutralization of Input During Web Page Generation' (Cross-site Scripting).
5
How can I fix the vulnerability CVE-2021-3830 in btcpayserver?
To fix the vulnerability CVE-2021-3830 in btcpayserver, update to a version higher than 1.2.3.