VYPR

AdminLTE

by Pi Hole

CVEs (8)

  • CVE-2020-8816HigKEVMay 29, 2020
    risk 0.61cvss 7.2epss 0.78

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

  • CVE-2023-23614HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes…

  • CVE-2021-32706HigAug 4, 2021
    risk 0.57cvss 7.6epss 0.60

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code,…

  • CVE-2021-29448HigApr 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch…

  • CVE-2022-23513MedDec 23, 2022
    risk 0.41cvss 5.3epss 0.40

    Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of…

  • CVE-2021-32793MedAug 4, 2021
    risk 0.37cvss 5.7epss 0.01

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-scripting vulnerability.…

  • CVE-2022-31029MedJul 7, 2022
    risk 0.00cvss 5.9epss 0.00

    AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `` in the field marked with "Domain to look for" and hitting enter (or clicking on any of the buttons) will execute the script. The user…

  • CVE-2021-41175HigOct 26, 2021
    risk 0.00cvss 7.3epss 0.01

    Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was…