PT-2022-7091 · Pi-Hole · Pi-Hole
Sopwnd
·
Published
2022-12-22
·
Updated
2025-04-11
·
CVE-2022-23513
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pi-Hole (affected versions not specified)
Description
The issue is related to a lack of validation in the code on a root server path:
/admin/scripts/pi-hole/phpqueryads.php. This allows a potential threat actor to perform an unauthorized query for blocked domains on the queryads endpoint, potentially leading to the disclosure of victims' personal blacklists. The vulnerability is associated with inadequate access control in the Pi-hole AdminLTE dashboard.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pi-Hole