{"id":"GHSA-33gv-rvgq-gpxp","summary":"Withdrawn Advisory: HTML injections in BTCPayServer","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because all of the files affected by this vulnerability lie in the [BTCPayServer folder](https://github.com/btcpayserver/btcpayserver/tree/master/BTCPayServer), which is not in the NuGet ecosystem. The [BTCPayServer folder](https://github.com/btcpayserver/btcpayserver/tree/master/BTCPayServer.Client), corresponding to the [BTCPayServer NuGet entry](https://www.nuget.org/packages/BTCPayServer.Client), does not contain any files that were changed to fix the vulnerability.\n\n## Original Description\nImproper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.","aliases":["CVE-2023-0493"],"modified":"2026-09-10T03:49:50.967474527Z","published":"2023-01-27T00:30:18Z","withdrawn":"2023-10-10T21:18:09Z","database_specific":{"github_reviewed_at":"2023-02-04T00:30:29Z","nvd_published_at":"2023-01-26T23:15:00Z","cwe_ids":["CWE-74","CWE-76"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0493"},{"type":"WEB","url":"https://github.com/btcpayserver/btcpayserver/pull/4545/commits/02070d65836cd24627929b3403efbae8de56039a"},{"type":"WEB","url":"https://github.com/btcpayserver/btcpayserver/commit/02070d65836cd24627929b3403efbae8de56039a"},{"type":"WEB","url":"https://huntr.dev/bounties/3a73b45c-6f3e-4536-a327-cdfdbc59896f"},{"type":"WEB","url":"http://packetstormsecurity.com/files/171732/BTCPay-Server-1.7.4-HTML-Injection.html"}],"affected":[{"package":{"name":"BTCPayServer.Client","ecosystem":"NuGet","purl":"pkg:nuget/BTCPayServer.Client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.5"}]}],"versions":["1.0.4.2","1.0.4.3","1.0.4.4","1.0.4.5","1.0.4.6","1.0.4.7","1.0.4.8","1.1.0","1.1.1","1.2.0","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-33gv-rvgq-gpxp/GHSA-33gv-rvgq-gpxp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}