CVE-2021-29448
Stored DOM XSS in Pi-hole Admin Web Interface
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
Pi-hole es una aplicaciĆ³n de bloqueo de anuncios y rastreadores de Internet a nivel de red de Linux. El ataque XSS Almacenado se presenta en el portal de AdministraciĆ³n de Pi-hole, que puede ser explotado por el actor malicioso con acceso de red al servidor DNS. Consulte el aviso de seguridad de GitHub al que se hace referencia para los detalles del parche
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-03-30 CVE Reserved
- 2021-04-15 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-cwwf-93p7-73j9 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pi-hole Search vendor "Pi-hole" | Ftldns Search vendor "Pi-hole" for product "Ftldns" | 5.7 Search vendor "Pi-hole" for product "Ftldns" and version "5.7" | - |
Affected
| ||||||
Pi-hole Search vendor "Pi-hole" | Pi-hole Search vendor "Pi-hole" for product "Pi-hole" | 5.2.4 Search vendor "Pi-hole" for product "Pi-hole" and version "5.2.4" | - |
Affected
| ||||||
Pi-hole Search vendor "Pi-hole" | Web Interface Search vendor "Pi-hole" for product "Web Interface" | < 5.5 Search vendor "Pi-hole" for product "Web Interface" and version " < 5.5" | - |
Affected
|