Medium severity6.1NVD Advisory· Published Dec 24, 2020· Updated Jun 17, 2026
CVE-2020-35659
CVE-2020-35659
Description
The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query Log page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Pi-hole/Pi-holedescription
Patches
Vulnerability mechanics
References
3- github.com/pi-hole/AdminLTE/pull/1665nvdPatchThird Party Advisory
- blog.mirch.io/2020/12/24/pihole-xss/nvdThird Party Advisory
- discourse.pi-hole.net/t/pi-hole-core-web-v5-2-2-and-ftl-v5-3-3-released/41998nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.