BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
History

Thu, 27 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-27T18:38:13.458Z

Reserved: 2022-06-10T00:00:00.000Z

Link: CVE-2022-32984

cve-icon Vulnrichment

Updated: 2024-08-03T07:54:03.456Z

cve-icon NVD

Status : Modified

Published: 2023-01-31T22:15:08.000

Modified: 2025-03-27T19:15:44.950

Link: CVE-2022-32984

cve-icon Redhat

No data.