VYPR
High severity7.3NVD Advisory· Published Oct 26, 2021· Updated Jun 17, 2026

CVE-2021-41175

CVE-2021-41175

Description

Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was patched in version 5.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Pi Hole/Web Interfacellm-fuzzy2 versions
    <5.8+ 1 more
    • (no CPE)range: <5.8
    • cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:*range: <5.8
  • Pi Hole/Pi Holellm-fuzzy
    Range: <5.8
  • pi-hole/AdminLTEv5
    Range: < 5.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.