Pi-Hole · Pi-Hole · CVE-2021-41175
**Name of the Vulnerable Software and Affected Versions**
Pi-hole versions prior to 5.8
**Description**
The issue affects Pi-hole's Web interface, which is based on AdminLTE, allowing for cross-site scripting when adding a client via the groups-clients management page. This issue was patched in version 5.8.
**Recommendations**
For versions prior to 5.8, update to version 5.8 to resolve the issue. As a temporary workaround, consider restricting access to the groups-clients management page until the update is applied.