
BTCPayServer Version 1.7.5 und darunter ist anfällig für Open-Redirection-Angriffe.
BTCPayServer 1.7.5 und niedrigere Versionen sind anfällig für Open-Redirection-Angriffe.
Schritte zur Reproduktion
https://mainnet.demo.btcpayserver.org/login
Aktivieren Sie das Kontrollkästchen I have written down my recovery phrase and stored it in a secure location
Klicken Sie dann auf Done
Sie werden zu evil.com weitergeleitet.
• Jefferson Gonzales (Gonz)
• Link: https://twitter.com/gonzxph