PT-2022-21138 · Adguard+1 · Adguardhome+1
Published
2022-10-11
·
Updated
2024-11-22
·
CVE-2022-32175
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
AdGuardHome versions v0.95 through v0.108.0-b.13
Description
The issue affects the custom filtering rules functionality, where an attacker can exploit it to delete or modify these rules by persuading an authorized user to follow a malicious link. This is a result of a Cross-Site Request Forgery (CSRF) vulnerability.
Recommendations
For versions v0.95 through v0.108.0-b.13, update to a version newer than v0.108.0-b.13, specifically v0.108.0-b.16 or later, where the file containing the vulnerable code is no longer present.
As a temporary workaround, consider restricting access to the custom filtering rules functionality until a patch is available.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Adguardhome