Authenticated XSS in Pi-hole AdminLTE
CVE-2022-31029

5.9MEDIUM

Key Information:

Vendor

Pi-hole

Status
Vendor
CVE Published:
7 July 2022

What is CVE-2022-31029?

AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like <script>alert("XSS")</script> in the field marked with "Domain to look for" and hitting enter (or clicking on any of the buttons) will execute the script. The user must be logged in to use this vulnerability. Usually only administrators have login access to pi-hole, minimizing the risks. Users are advised to upgrade. There are no known workarounds for this issue.

Affected Version(s)

AdminLTE < 5.13

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.