PT-2025-6854 · Unknown · Pihome-Shc Pihome
Jelle Janssens
·
Published
2025-02-12
·
Updated
2025-02-12
·
CVE-2025-1213
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
pihome-shc PiHome version 1.77
Description
A problem has been found in the /index.php file, affecting some unknown functionality. The issue is related to the manipulation of the
$ SERVER['PHP SELF'] argument, which leads to cross site scripting. This can be exploited remotely.Recommendations
For pihome-shc PiHome version 1.77, consider disabling the
$ SERVER['PHP SELF'] argument in the /index.php file as a temporary workaround until a patch is available. Restrict access to the /index.php file to minimize the risk of exploitation. Avoid using the $ SERVER['PHP SELF'] argument in the affected file until the issue is resolved.Exploit
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pihome-Shc Pihome