Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-0748 — BTCPayServer version 1.7.5 and below is vulnerable for Open Redirection attack. | Kitploit
Tools/GitHubGitHub/gonzxph/cve-2023-0748
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubgonzxph/cve-2023-0748

CVE-2023-0748

BTCPayServer version 1.7.5 and below is vulnerable for Open Redirection attack.

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-0748

BTCPayServer 1.7.5 and lower version is vulnerable for Open Redirection attack.

Step to Reproduce

  1. Login your account on

https://mainnet.demo.btcpayserver.org/login

  1. Then Click the link below

https://mainnet.demo.btcpayserver.org/recovery-seed-backup?cryptoCode=BTC&mnemonic=above&passphrase=&isStored=false&requireConfirm=true&returnUrl=//evil.com

  1. Check the I have written down my recovery phrase and stored it in a secure location

  2. Then click Done

You will be redirected to evil.com



Credits

• Jefferson Gonzales (Gonz)
• Link: https://twitter.com/gonzxph

Download Tool