VYPR
High severity7.8NVD Advisory· Published Jun 23, 2020· Updated Jun 17, 2026

CVE-2020-14971

CVE-2020-14971

Description

Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them. This occurs in settings.php. To exploit this, an attacker would request a backup of limited files via teleporter.php. These are placed into a .tar.gz archive. The attacker then modifies the host parameter in dnsmasq.d files, and then compresses and uploads these files again.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Pi Hole/Pi Hole2 versions
    cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pi-hole:pi-hole:*:*:*:*:*:*:*:*range: <=5.0
    • (no CPE)range: <=5.0
  • Pi-hole/Pi-holedescription
  • Range: <=5.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.