BTCPayServer 1.7.5 and lower version is vulnerable for Open Redirection attack.
Step to Reproduce
- Login your account on
https://mainnet.demo.btcpayserver.org/login
- Then Click the link below
-
Check the
I have written down my recovery phrase and stored it in a secure location
-
Then click
Done
You will be redirected to evil.com
• Jefferson Gonzales (Gonz)
• Link: https://twitter.com/gonzxph