PT-2021-11811 · Pi-Hole · Pi-Hole

N4Nj0

·

Published

2021-02-18

·

Updated

2021-02-24

·

CVE-2020-35592

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Pi-hole versions 5.0 through 5.1.1
Description: The issue allows a remote user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data, achieving a Reflected Cross-Site Scripting attack against other users and potentially stealing the session cookie. This is done via the Options header to the "admin/" URI.
Recommendations: For versions 5.0 through 5.1.1, consider disabling access to the "admin/" URI until a patch is available to prevent exploitation. Restrict the use of the Options header in the admin/ URI to minimize the risk of Reflected Cross-Site Scripting attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35592

Affected Products

Pi-Hole