Search/CVE-2021-32793
CVE — Medium

CVE-2021-32793

Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-scripting vulnerability. User input added as a wildcard domain to a blocklist or allowlist is unfiltered in the web interface. Since the payload is stored permanently as a wildcard domain, this is a persistent XSS vulnerability. A remote attacker can therefore attack administrative user accounts through client-side attacks. Pi-hole Web Interface version 5.5.1 contains a patch for this vulnerability.

CVSS v3.1
5.7 MEDIUM
EPSS
0.79%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityHIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:H
Connections
2 relationships
Timeline
disclosure → media coverage
Aug 4, 2021
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024