PT-2026-30628 · Pi-Hole · Pi-Hole Admin Interface
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pi-hole Admin Interface versions 6.0 through 6.4
Description
Configuration values from the '/api/config' endpoint are inserted into HTML value attributes without proper escaping in settings-advanced.js, allowing HTML attribute injection. A double quote in a configuration value allows an attacker to break out of the attribute context. While the server's Content Security Policy (CSP)—a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS)—prevents JavaScript execution, injected attributes can be used for UI redressing by altering element styling. The main attack vector involves importing a malicious teleporter backup, which bypasses server-side validation for individual fields.
Recommendations
Update Pi-hole Admin Interface to version 6.5.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pi-Hole Admin Interface