Security Advisory

CVE-2021-29246

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-05 12:25:43
Last updated 2024-08-03 22:02:51
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload the file outside of the restricted directory.