Search/CVE-2022-31029
CVE — Medium

CVE-2022-31029

AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like alert("XSS") in the field marked with "Domain to look for" and hitting enter (or clicking on any of the buttons) will execute the script. The user must be logged in to use this vulnerability. Usually only administrators have login access to pi-hole, minimizing the risks. Users are advised to upgrade. There are no known workarounds for this issue.

CVSS v3.1
5.9 MEDIUM
EPSS
0.45%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 1, 2026
0.01pp
0.44% → 0.45% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityLOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
Jul 7, 2022
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024