Search/CVE-2021-29448
CVE — High

CVE-2021-29448

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.

CVSS v3.1
7.6 HIGH
EPSS
0.67%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityHIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Connections
4 relationships
Timeline
disclosure → media coverage
Apr 15, 2021
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024