Cross Site Scripting Vulnerability in PiHome 2.0 by pihome-shc
CVE-2025-1742
Key Information:
- Vendor
- Pihome-shc
- Status
- Pihome
- Vendor
- CVE Published:
- 27 February 2025
Badges
Summary
A significant cross site scripting vulnerability exists in the PiHome 2.0 product by pihome-shc, particularly affecting the /home.php file. The vulnerability allows an attacker to manipulate the 'page_name' argument, which may lead to malicious scripts being executed in the context of a victim's browser. This security flaw can be exploited remotely, making it a critical issue for users who may not be aware of potential exploits. The security implications have been made public, and no response from the vendor has been noted regarding the disclosure.
Affected Version(s)
PiHome 2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved