VYPR
Unrated severityNVD Advisory· Published Oct 26, 2021· Updated Aug 4, 2024

Stored XSS in Client Groups Management (Authenticated)

CVE-2021-41175

Description

Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was patched in version 5.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.