VYPR
Medium severity5.4NVD Advisory· Published Feb 18, 2021· Updated Jun 17, 2026

CVE-2020-35592

CVE-2020-35592

Description

Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the session cookie.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Pi Hole/Pi Hole4 versions
    cpe:2.3:a:pi-hole:pi-hole:5.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:pi-hole:pi-hole:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:pi-hole:pi-hole:5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:pi-hole:pi-hole:5.1:*:*:*:*:*:*:*
    • (no CPE)range: 5.0, 5.1, and 5.1.1
  • Pi-hole/Pi-holedescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.